Repository navigation
fix: hide unpublished GenesisRAG17 entities from legacy reads - #18
Merged
Merged
Conversation
Proposed in ADR-GKS-PIPELINE-VISIBILITY (awaiting owner approval). - Migration 0007 adds a GKS-owned entities.origin column. Only the pipeline submit writer sets 'pipeline'. The backfill marks a row pipeline-origin only when a run recorded it and the legacy path never created it, and adds an entity_id-leading index on pipeline_mentions. - search, getEntity (and so relations_get and artifact_link), getRelations, the legacy resolution pool (so resolveTo too) and D9 BIND/MERGE operands hide pipeline entities until a mentioning run is PUBLISHED. Stage 9 reuse opts in with includeUnpublishedPipeline. - A legacy norm key that imitates a hidden typed pipeline key is created under the D2 discriminator instead of surfacing gks_conflict. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- The owner approved ADR-GKS-PIPELINE-VISIBILITY (0.2.0, accepted 2026-09-27). - D4 is now enforced in code: a D9 MERGE whose supersededRef is a pipeline-origin entity is refused with gks_conflict, because Stage 9 reuse finds pipeline entities by deterministic id and does not follow supersession. A pipeline entity can still be the survivor. Covered by a test and mutation-checked. - D3 notes that after publication an imitation string can resolve AMBIGUOUS. - Revision rows in the data model, port contract, C0 qualification and GenesisRAG17 ADRs now reference the accepted decision. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ion-visibility # Conflicts: # docs/ADR-GKS-GENESISRAG17.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GenesisRAG17 writes its canonical entities into
entitiesat submit, before Stage 17 has gated anything. As a result, entities fromPENDING,REJECTEDandFAILED_STAGEruns were:gks_search,gks_entity_get,gks_relations_getandgks_artifact_link;MATCHEDresult, or aresolveToexistence probe).The gap analysis found this and it was deferred from #17. This PR is the ADR-first redo that the architecture review asked for.
Rule (D1): a pipeline-origin entity is visible to legacy reads only after a run that mentions it is
PUBLISHED. Publication is one-way.0007addsentities.origin. Only the pipeline submit writer sets'pipeline', so no request field, metadata key or norm key can set it.'pipeline'only if a run recorded it and the legacy path never created it (noCREATEDmention).entity_id-leading index for the visibility check.search,getEntity(and through itrelations_getandartifact_link),getRelations(D5), the legacy resolution pool (D3, which also coversresolveTo) and D9 BIND/MERGE operands (D4).includeUnpublishedPipeline: true, so repeated runs still converge on one identity.norm_v1keeps U+0000 and caseless types). When that happens the legacy entity is created under the existing D2 discriminator, rather than agks_conflictthat would reveal the hidden row.Requirements addressed from the SRS blueprint:
GKS-GOV-002and the legacy-read half ofGKS-RET-002.Known limits (recorded in the ADR)
gks_conflict.0007is refused (GKS_SCHEMA_AHEAD). Roll back by restoring the pre-migration backup.Test plan
npm testafter merging fix: close P0 gaps from the SRS blueprint gap analysis #17 into this branch: vitest 237 passed, 2 skipped (MSP integration suites needMSP_REPO_ROOT); security 12/12pipeline-genesisrag17.test.mjs):PENDING/REJECTED/FAILED_STAGE, and visible after publication;resolveTo-probes a hidden entity;metadata.pipelineVersionstays visible;0007, including a legacy entity that pipeline reuse has claimed.entity_get,search,relations_get,artifact_link,resolveTo), and the legacy pool excludes it.CREATEDclause fails the backfill test.FAILED_STAGE/resolveTotests) is addressed in this commit.AMBIGUOUS) match that occurs after publication for an imitation string.ADR-GKS-PIPELINE-VISIBILITY(accepted 2026-09-27)🤖 Generated with Claude Code