Native command concurrency verification
Run node scripts/db-native-concurrency-tests.mjs after migration application and the rolled-back launch suite in scripts/db-flow-tests.sh. It uses the existing DATABASE_URL and targets debelu_flow_tests, or accepts FLOW_TEST_URL for that database or debelu_concurrency_tests. Only local/CI hostnames are accepted. The database must be disposable: fixture records commit and are removed by recreating the database on the next run.
The runner requires the native psql client and PostgreSQL 15+. It does not use PGlite, contact Paystack, dispatch notifications through an external provider, or alter hosted databases. It creates its own buyer, vendor, role, canonical product/order, and verified privacy case through the real migrated schema with all triggers enabled.
Each race holds an open transaction in one PostgreSQL process and starts a second independent process. A third observer confirms an actual pg_stat_activity lock wait before the first transaction commits. Lock and statement deadlines make missing synchronization or regressions fail instead of hanging CI.
Assertions cover a single checkout reservation claim/payment row, duplicate dispatch rejection, uncertain intent replay without a new claim, immutable provider reference/request identity, privacy template revocation, account suspension, case review holds, and a review waiting behind accepted preparation. A newly reviewed case must refuse the older artifact download and remain incomplete. These tests establish transaction ordering for the named races; they do not certify provider idempotency or full privacy execution across systems.
Local status on 4 October 2026: script syntax checked; native execution unavailable because psql is absent and the Docker Linux engine is stopped. No native concurrency passing result is claimed until CI executes the runner.