diff --git a/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md b/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md index 9f7ce802..b4194c05 100644 --- a/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md +++ b/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md @@ -23,8 +23,9 @@ without materialized snapshot or projection files. with the recovered frontier. - Both paths compare pre-reopen and post-reopen query results. Those equality checks can pass if a materialized file was not removed. -- The focused target passes 2/2 on the current mainline; that is baseline - result-comparison evidence only. +- At pre-fix baseline `aed35b7f5dee320a703b41db035d30daa71139ee`, the focused + target passed 2/2; this was result-comparison evidence only and predates the + merged correction. ## Root Cause @@ -53,8 +54,8 @@ therefore mistaken for proof of the recovery path. 5. Keep this correction test-only in tests/g3_oracle_differential_tests.rs, then run the focused target and its specified G1/G2/crash regression matrix. 6. Report WAL-only recovery as NOT_PROVEN until these assertions are - implemented and pass. Do not promote this test result to hosted CI, - power-loss, release, deployment, or broad P7 evidence. + implemented and pass; after they pass, claim only the bounded test proof. + Do not promote it to power-loss, release, deployment, or broad P7 evidence. ## Implementation follow-up — CI Clippy failure (2026-10-06) @@ -91,9 +92,29 @@ not exercise the same lint acceptance check as CI. `cargo clippy --no-default-features --all-targets -- -D warnings` and `cargo clippy --all-targets -- -D warnings`. +## Resolution — PR #217 merged 2026-10-06 + +The test-evidence root cause is resolved for the bounded `g3.oracle.v1` proof. +The merged correction makes materialized-file removal fail closed, verifies +those files are absent before reopen, and checks that the recovered stable +frontier covers the final pre-close frontier. Exact query/oracle comparisons +remain in place. + +PR #217 head `9221b74e7dd81c350e099ac6b4a034810971d9b0` merged as +`987bf32507af6e1f9cc612385db093b4358996ed`. Hosted Tests, Security Audit, +GenesisRAG17 Linux worker, Performance Audit, and Package Manager Consumer +checks passed. The Linux worker had 26 passes, 0 failures, and 6 skips because +the pinned ONNX model snapshot was absent. The former Clippy issue was fixed +with `std::io::Error::other(...)` and the hosted checks passed. + +Closure is limited to the named test proof and CI checks. Physical power-loss, +mobile/device, migration, release, deployment, and production acceptance are +not established by this RCA resolution. + ## Version Diff | From | To | Change | |---|---|---| | none | 1.0.0 | Record the G3 WAL-only recovery test-evidence root cause and bounded prevention criteria. | | 1.0.0 | 1.0.1 | Record the PR #217 Clippy failure, evidence, root cause, and lint-gate prevention. | +| 1.0.1 | 1.0.2 | Record resolution of the bounded G3 test-evidence gap on merged PR #217, including hosted checks and skipped-test limits. | diff --git a/docs/MASTER_PLAN.md b/docs/MASTER_PLAN.md index 97215172..39966911 100644 --- a/docs/MASTER_PLAN.md +++ b/docs/MASTER_PLAN.md @@ -1,7 +1,7 @@ --- status: current -version: "0.2.1" -updated: "2026-08-14" +version: "0.2.2" +updated: "2026-10-06" owner: "Boss (Founder / Product Authority)" approval: "Approved in-session 2026-08-14" --- @@ -36,7 +36,7 @@ adapter as implemented. The governing decisions are: | HQL P0 correctness work | Implemented and merged on `main`; retained as compatibility baseline. | | HQL P1/P2/P3 expansion | Deferred; not required for the primary public contract. | | Typed Query IR ADR/spec | Accepted by owner on 2026-08-14. | -| Typed Query IR executor/API | Partial: `search` and `traverse` implemented across core, REST and N-API; remaining operation kinds planned. | +| Typed Query IR executor/API | Partial: source implementations exist for `search`, `traverse`, `match_path`, and target-ID `context`; W1 conformance is not freshly verified end-to-end. `relational_named_query` remains unsupported. | | NL-to-Query-IR adapter | Planned outside the engine; not implemented. | | Engine package/release | Remains a productization gate; acceptance requires registry/install evidence. | @@ -62,7 +62,7 @@ model/provider work cannot block the database engine or leak into its core. | Wave | Scope | Deliverable | Exit criteria | |---|---|---|---| | W0 | Architecture boundary | Accepted ADR/spec, registry/C4/parent-doc alignment, this plan | Documentation validators pass; implementation status remains truthful. | -| W1 | Typed Query IR | Closed V1 schema, Rust typed executor, N-API/REST bindings, capability reporting, HQL mapping | Search/traverse vertical slice passes core, REST and N-API parity; HQL compatibility fixtures pass. | +| W1 | Typed Query IR contract/conformance closure | Freeze the standalone V1 schema and fixtures; characterize existing core behavior; close HQL, REST, and N-API parity gaps for supported operations | Shared schema/fixture gates pass; supported operations meet the accepted V1 contract across declared surfaces; unsupported operations fail closed. | | W2 | Publish engine | Release tag/matrix, platform prebuilds, package docs/security/version alignment | Clean-machine install and smoke evidence; no path-dependent dependency. | | GATE-DEMAND-1 | Demand evidence | First-10-external-installs record over an owner-defined measurement window | Owner records proceed, pivot or stop before expensive adapter/channel work. | | W3 | External NL adapter | Separate provider-neutral adapter package producing `QueryRequestV1`; MCP prefers typed operations | Schema/capability/auth rejection and ambiguous-intent fail-closed tests pass; engine has no LLM dependency. | @@ -79,19 +79,23 @@ model/provider work cannot block the database engine or leak into its core. | W3 NL adapter | `TQIR-009`, ADR agent-boundary rules | Outside engine, schema-validated and fail closed. | | W2/W4 distribution | `GB-SRS-NFR-005`, `GB-SRS-NFR-007..008` | Installability, compatibility and security evidence. | -## 5. First implementation slice (W1) +## 5. W1 contract/conformance closure -The first slice is deliberately bounded: +W1 is a verification-and-gap-closure wave over the current Typed Query IR V1 +implementation, not a rewrite of the executor or a claim that all reserved +operations are implemented. The current spec remains `partial`. The proposed +queue and execution graph are `queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json` and +`queue/QUERY_IR_W1_PROJECT_GRAPH.json`; both are non-dispatchable until the +owner reviews and accepts the W1 plan and separately authorizes implementation. -1. Freeze JSON Schema plus Rust request/result enums for `search` and `traverse`. -2. Add RED tests for validation, unsupported versions, bounds and collection mismatch. -3. Implement one typed core dispatcher over existing storage methods. -4. Expose N-API and REST routes with equivalent envelopes. -5. Map HQL `SEARCH` and `TRAVERSE` to the typed dispatcher and run parity fixtures. -6. Report operation support through capability/version output. - -`match_path`, `context` and `relational_named_query` are reserved V1 operation kinds but require their -own closed schemas and acceptance tests before being reported as implemented. +The proposed sequence freezes a standalone closed V1 schema and shared fixtures, +characterizes current behavior, then closes only evidence-backed conformance +gaps across core, HQL compatibility, REST, and N-API. Existing `search`, +`traverse`, `match_path`, and target-ID `context` behavior must be measured +against the accepted schema and capability contract before any status is +promoted. `relational_named_query` is not implemented and is out of scope for +this W1 queue. Existing HQL fallback behavior is preserved; W1 does not expand +or remove HQL. ## 6. Milestones @@ -113,14 +117,17 @@ own closed schemas and acceptance tests before being reported as implemented. | R3 | NL model emits valid-looking unauthorized queries | 4 | 5 | 20 | Treat output as untrusted; schema, capability and caller-policy validation; fail closed. | | R4 | V1 becomes an unrestricted JSON escape hatch | 3 | 5 | 15 | Closed discriminated types; reject unknown fields; no generic payload. | | R5 | Cross-surface contract version drift | 3 | 4 | 12 | Shared fixtures and capability-version conformance in CI. | -| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to search/traverse vertical slice; reserve other operations. | +| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to conformance closure for existing supported operations; exclude `relational_named_query` and require explicit scope review for additions. | | R7 | No external demand after publish | 3 | 5 | 15 | Preserve GATE-DEMAND-1 before expensive adapter/channel work. | | R8 | Graphiti requires broader Cypher semantics | 3 | 3 | 9 | Inspect upstream contract before W5; adapt typed IR rather than expanding HQL automatically. | ## 8. Scope boundaries -In scope now: architecture docs, V1 contract, master-plan alignment and the completed W1 -`search`/`traverse` vertical slice. Remaining V1 operations require separate slices. +In scope now: architecture/docs reconciliation and a proposed W1 execution plan. +The plan targets contract/conformance evidence for existing `search`, `traverse`, +`match_path`, and target-ID `context` implementations. This document approval +does not authorize W1 code changes. `relational_named_query` and all other +unsupported modes remain outside the proposed queue. Out of scope until its wave is approved/executed: @@ -145,8 +152,11 @@ The previous `33_TASK_BREAKDOWN.md`, `36_TASK_EXECUTION_ORDER.md`, `PHASE_6_REVI `queue/IMPLEMENTATION_QUEUE.json` and `queue/PROJECT_GRAPH.json` describe the superseded HQL-first sequence. They are retained as historical evidence with `source_of_truth: false` where machine-readable. -The next planning action is to decompose W1 from the accepted Query IR V1 requirements and submit the -replacement queue/graph for review. Until that happens, no old `ready: true` flag authorizes dispatch. +The proposed W1 queue/graph are review artifacts only: `status: proposed`, +`source_of_truth: false`, `ready: false`, and `dispatch_authorized: false`. +The superseded HQL-first queue and graph remain unchanged. No task may dispatch +until the owner accepts the replacement plan and separately authorizes W1 +implementation; historical `ready: true` flags confer no authority. ## CHANGELOG @@ -154,4 +164,5 @@ replacement queue/graph for review. Until that happens, no old `ready: true` fla |---|---|---|---|---|---| | 0.2.0 | 2026-08-14 | current | Approved Typed Query IR as pre-publish contract, retained HQL compatibility and moved NL conversion to an external post-publish adapter wave. | working-tree | ATHER | | 0.2.1 | 2026-08-14 | current | Recorded completion of the W1 search/traverse vertical slice across core, REST and N-API while retaining remaining V1 operations as planned. | working-tree | ATHER | +| 0.2.2 | 2026-10-06 | current | Reconciled W1 to existing Query IR operation implementations; reframed the next wave as non-dispatchable conformance closure, excluding relational_named_query. | working-tree | Codex | | 0.1.0 | 2026-07-07 | superseded | Initial engine-wedge distribution plan centered on HQL P0 and four distribution waves. | historical | ATHER | diff --git a/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html b/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html index 8dee5f18..0878a436 100644 --- a/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html +++ b/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html @@ -71,7 +71,7 @@

G3 recovery proof · execution dependencies

G3 recovery proof execution dependencies - Four ranked dependency layers show the pending model and code authorization prerequisite, one-file test worker, parallel Verify and Review gates, and a Final Gate that does not authorize merge. + Four ranked dependency layers show the selected gpt-6-luna Max worker, merged G3 test correction, Verify and Review gates, and a Final Gate. PR 217 is merged; the diagram records evidence and does not authorize a separate merge. @@ -129,7 +129,7 @@

G3 recovery proof · execution dependencies

WORKER 2 IN - Test-only Worker + G3 Test-only Worker one source test file @@ -139,8 +139,8 @@

G3 recovery proof · execution dependencies

GATE 1 IN - Model + Code Gate - docs approved · choice pending + Model + Scope Gate + gpt-6-luna Max · authorization cleared LEGEND @@ -155,7 +155,7 @@

G3 recovery proof · execution dependencies

-

Current hold: documentation is approved, but the requested gpt-5.6-luna Max effort is not advertised here; no substitute is selected. No source worker starts until a supported model and code-scope authorization are explicit. A failed gate stops the candidate; any corrected candidate must rerun Verify, Review, and Final. Final PASS does not authorize commit, push, or merge.

+

G3 status: PR #217 (head 9221b74, merge 987bf32) is merged. Hosted checks passed; the Linux worker reported 26 passed, 0 failed, and 6 skipped because the pinned ONNX model snapshot was absent. The selected gpt-6-luna Max worker choice and scoped authorization are historical workflow context, not a claim about which runtime executed CI. Power-loss hardware, mobile/device, release, deployment, and production acceptance remain unverified. A failed gate stops its candidate; corrections rerun Verify, Review, and Final. This evidence does not authorize a separate commit, push, or merge.

diff --git a/docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md b/docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md index de07b8b7..736acd9c 100644 --- a/docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md +++ b/docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md @@ -1,9 +1,9 @@ --- doc_id: SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY owner: GenesisBlockDB Engineering -version: 0.1.2b +version: 0.1.3b created_at: "2026-10-04T00:00:00+07:00,Codex,working-tree" -last_update: "2026-10-06T06:30:22+07:00,Codex" +last_update: "2026-10-06T18:44:54+07:00,Codex" status: draft superseded_by: null attributes: @@ -99,9 +99,10 @@ kept empty so the gate is reproducible without a network install. ## Non-goals and evidence boundary -This spec does not prove hosted CI, power-loss hardware behavior, mobile/device -behavior, release packaging, planner correctness, or production readiness. -Those remain NOT_RUN until their named external gates execute. +The bounded hosted checks for PR #217 are recorded below; they do not establish +physical power-loss behavior, mobile/device behavior, release packaging, planner +correctness, or production readiness. Those broader gates remain NOT_RUN until +their named external evidence is available. ## Local execution evidence — 2026-10-04 (historical baseline) @@ -114,26 +115,38 @@ the 60-build probe_vs_recall target and crate doc-tests. These historical results establish query-oracle and regression evidence, not the WAL-only precondition now specified above. -## Recovery-proof evidence review — 2026-10-06 - -On the current mainline, the focused Rust target passes 2/2 as a baseline. -Inspection found that remove_materialized_state discards all file-removal -errors and the temporal and relational paths do not assert a post-reopen stable -frontier. Therefore the baseline does not prove that materialized state was -absent or that the recovered frontier covers every durable fixture mutation. -Status: result comparison locally verified; WAL-only recovery proof -NOT_PROVEN; correction implementation and its verification are pending. -This is a test-evidence finding, not a confirmed storage-engine defect. The -bounded correction does not close broad HQL2 P7 or any external release gate. - -This is local working-tree evidence only. Hosted CI, power-loss hardware, -mobile/device, release packaging, deployment, independent review, and -production acceptance are NOT_RUN. G4+ remains deferred. +## Recovery-proof evidence review — PR #217 merged 2026-10-06 + +The pre-correction baseline at `aed35b7f5dee320a703b41db035d30daa71139ee` +passed the focused target 2/2 but did not prove WAL-only recovery: removal +errors were discarded and the final recovered frontier was not asserted. +PR #217 addressed that test-evidence gap on head +`9221b74e7dd81c350e099ac6b4a034810971d9b0`, merged as +`987bf32507af6e1f9cc612385db093b4358996ed`. + +The merged test correction now fails on non-NotFound removal errors, asserts +the listed materialized files are absent before reopen, and requires the +recovered stable frontier to cover the final pre-close frontier while retaining +exact pre/post and oracle-result equality. The PR's hosted checks all passed: +Tests (run `37445626527`), Security Audit (`37445626873`), GenesisRAG17 Linux +worker (`37445626662`), Performance Audit (`37445626416`), and Package Manager +Consumer (`37445626577`). The Linux worker exercised 32 tests: 26 passed, 0 +failed, and 6 were skipped because the pinned ONNX model snapshot was absent. + +Status: the bounded `g3.oracle.v1` WAL-only test proof is verified on the merged +source for the stated gates. The six skipped model-backed cases are not +verified. This is test-level recovery evidence, not physical power-loss proof. +Power-loss hardware, mobile/device behavior, planner correctness, migration +compatibility, release packaging, deployment, and production acceptance remain +NOT_RUN. Broad HQL2 P7 remains open. G4 remains PARTIAL per +`docs/IMPLEMENTATION-PLAN--UEE-HQL2-ORCHESTRATION-2026-09-22.md`; this G3 +evidence does not change that status or close later HQL2 gates. ## CHANGELOG | Version | Date | Status | Summary | Commit | Agent | |---|---|---|---|---|---| +| 0.1.3b | 2026-10-06 | draft | Reconcile G3 evidence to merged PR #217 and passing hosted checks; retain the six ONNX-dependent skips and external proof boundaries. | working-tree | Codex | | 0.1.2b | 2026-10-06 | draft | Specify fail-closed materialized-file removal and recovered-frontier assertions; downgrade the current 2/2 baseline to NOT_PROVEN for WAL-only recovery until the assertions exist and pass. | working-tree | Codex | | 0.1.1b | 2026-10-04 | candidate | Added local Python and Rust differential/reopen evidence for the bounded g3.oracle.v1 fixture; external gates remain NOT_RUN. | working-tree | Codex | | 0.1.0b | 2026-10-04 | draft | Define a pure G3 oracle, canonical fixtures, differential comparison, and WAL-backed recovery rerun. | working-tree | Codex | diff --git a/queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json b/queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json new file mode 100644 index 00000000..ec575de8 --- /dev/null +++ b/queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json @@ -0,0 +1,562 @@ +{ + "id": "QUEUE-QUERY-IR-W1", + "type": "implementation_queue", + "title": "Typed Query IR V1 contract and conformance closure", + "version": "0.1.0", + "status": "proposed", + "source_of_truth": false, + "ready": false, + "dispatch_authorized": false, + "created_at": "2026-10-06T18:28:36+07:00", + "updated_at": "2026-10-06T18:28:36+07:00", + "source_sha": "987bf32507af6e1f9cc612385db093b4358996ed", + "parent_docs": [ + "docs/MASTER_PLAN.md", + "docs/SPEC--GENESISDB-TYPED-QUERY-IR-V1.md", + "docs/adr/ADR--GENESISDB-TYPED-QUERY-IR-AGENT-BOUNDARY.md", + "docs/C4--GENESISDB-ARCHITECTURE.md" + ], + "approval_gates": [ + { + "id": "G0", + "authority": "owner", + "purpose": "Approve this exact plan and scope; no code dispatch." + }, + { + "id": "D0", + "authority": "owner", + "purpose": "Separately authorize implementation after G0; until then all worker tasks remain disabled." + } + ], + "architecture_decision": { + "wave": "W1 is contract/conformance closure over existing implementations, not an executor rewrite.", + "implemented_source_slices": [ + "search", + "traverse", + "linear match_path", + "target-ID context" + ], + "unverified_boundary": "Source presence is not a fresh end-to-end conformance PASS; capability declarations and behavior must be verified.", + "not_implemented": [ + "relational_named_query" + ], + "preserve": [ + "HQL compatibility fallbacks", + "current public contracts unless a separately reviewed finding proves a mismatch" + ], + "out_of_scope": [ + "lexical-search expansion", + "new search filters or capabilities", + "namespace-scoped traversal", + "match_path tx_as_of", + "query-vector or temporal context", + "relational_named_query", + "HQL grammar expansion/removal", + "HQL2 planner/EXPLAIN", + "storage/WAL/ACL redesign", + "NL/provider integration", + "SDK/MCP feature expansion", + "packaging/publishing/release/deployment" + ] + }, + "agent_roles": { + "architecture_analysis": { + "model": "gpt-6-astra", + "reasoning_effort": "max", + "status": "analysis supplied; subject to owner review" + }, + "worker": { + "model": "gpt-6-luna", + "reasoning_effort": "max", + "status": "proposed; starts only after D0" + }, + "verify_gate": { + "kind": "deterministic", + "owner": "Codex coordinator", + "rule": "Run the listed commands on one candidate SHA; preserve exact outputs, exit codes, and skips." + }, + "review_gate": { + "model": "gpt-6-astra", + "reasoning_effort": "max", + "read_only": true + }, + "final_gate": { + "owner": "Codex coordinator", + "rule": "Fail closed unless Verify PASS, Review PASS, docs aligned, and acceptance criteria are evidenced." + } + }, + "parallelism": { + "rule": "Unordered tasks must have disjoint write_set values. Read-only audit/gates may overlap writers only when they inspect an immutable baseline and rerun after candidate changes.", + "parallel_stages": [ + [ + "H1", + "R1", + "X1" + ] + ], + "serialized_shared_file_tasks": [ + "S1 before F1", + "C0 before C1; merge C0+C1 atomically", + "H1 and R1 before N1 when N1 needs conditional src/lib.rs edits" + ], + "failure_rule": "A correction creates a new candidate revision and invalidates every dependent Verify/Review/Final result; do not merge RED-only or stale evidence." + }, + "atomic_merge_groups": [ + [ + "C0", + "C1" + ] + ], + "merge_stages": [ + { + "stage": 0, + "tasks": [ + "P0" + ], + "rule": "Documentation-only candidate; no implementation." + }, + { + "stage": 1, + "tasks": [ + "G0" + ], + "rule": "Owner accepts the exact plan; this does not authorize code." + }, + { + "stage": 2, + "tasks": [ + "D0" + ], + "rule": "Separate explicit owner authorization is required before any W1 worker starts." + }, + { + "stage": 3, + "tasks": [ + "S1" + ], + "rule": "Schema and validator dependency are reviewed before fixture consumers." + }, + { + "stage": 4, + "tasks": [ + "F1" + ], + "rule": "Shared fixtures land only after the schema test exists." + }, + { + "stage": 5, + "tasks": [ + "C0", + "C1" + ], + "rule": "One green core candidate; never merge intentional RED tests alone." + }, + { + "stage": 6, + "tasks": [ + "H1", + "R1", + "X1" + ], + "rule": "H1 and R1 may work in parallel with disjoint writes; X1 is evidence-only; merge code changes H1 then R1. X1 must complete before D1/V." + }, + { + "stage": 7, + "tasks": [ + "N1" + ], + "rule": "After H1/R1; conditionally owns any N-API binding correction after C1." + }, + { + "stage": 8, + "tasks": [ + "D1" + ], + "rule": "Reconcile docs after implementation evidence and before final validation/review." + }, + { + "stage": 9, + "tasks": [ + "V" + ], + "rule": "Integrated deterministic Verify on one candidate SHA, including all focused and full gates." + }, + { + "stage": 10, + "tasks": [ + "RV" + ], + "rule": "Independent read-only Astra Review of the verified final candidate." + }, + { + "stage": 11, + "tasks": [ + "FG" + ], + "rule": "Final Gate; external merge/release/deployment requires its own authority." + } + ], + "acceptance_criteria": [ + "A standalone closed Draft 2020-12 schema and shared fixtures define supported V1 envelopes without widening approved semantics.", + "Existing supported operation behavior is tested against the accepted schema and truthful capability declarations across core, HQL, REST, and N-API.", + "Unsupported capabilities, including relational_named_query, reject explicitly with stable typed errors and without semantic degradation.", + "Bounds, defaults, capability reporting, and error mappings in the shared fixtures are sourced from explicit contract decisions rather than inferred implementation values.", + "Existing HQL fallback behavior remains unchanged unless an accepted test proves a contract mismatch.", + "Focused and full required tests pass on the same candidate SHA; skipped work is reported as unverified.", + "Independent Astra Review and final provenance/scope gate pass; canonical docs identify exact evidence and remaining NOT_RUN items.", + "W1 claims conformance only for verified surfaces; the overall accepted spec remains partial while broader SDK/MCP/NL-adapter gates remain incomplete." + ], + "tasks": [ + { + "id": "P0", + "title": "Reconcile architecture docs and publish proposed W1 queue/graph", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [], + "write_set": [ + "docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md", + "docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html", + ".brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md", + "docs/MASTER_PLAN.md", + "queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json", + "queue/QUERY_IR_W1_PROJECT_GRAPH.json" + ], + "worker": "Codex coordinator; architecture input from gpt-6-astra Max", + "verify": [ + "npm run docs:validate", + "git diff --check" + ], + "exit": "Parent/peer documents agree, the prior G3 baseline is reconciled, and the replacement queue/graph are explicitly non-dispatchable." + }, + { + "id": "G0", + "title": "Owner approval of W1 plan and architecture boundary", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "P0" + ], + "write_set": [], + "owner": "User", + "verify": [ + "Explicit approval of the exact proposed queue/graph and non-goals" + ], + "exit": "Plan approval recorded; this gate alone does not authorize code dispatch." + }, + { + "id": "D0", + "title": "Separate owner authorization to dispatch W1 implementation", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "G0" + ], + "write_set": [], + "owner": "User", + "verify": [ + "Explicit code-dispatch authorization after G0" + ], + "exit": "Worker tasks may start only after this separate authorization." + }, + { + "id": "S1", + "title": "Freeze standalone Query IR V1 schema and schema-validation gate", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "D0" + ], + "write_set": [ + "docs/contracts/query-ir.v1.schema.json", + "package.json", + "package-lock.json", + "__test__/query_ir_schema.test.mjs" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "node --test __test__/query_ir_schema.test.mjs" + ], + "notes": "Use JSON Schema draft 2020-12. AJV is currently present transitively in package-lock; promote it to a direct test-only dependency and pin through the lockfile. No Rust dependency is needed for schema parsing; existing native typed validation remains separately tested.", + "exit": "Closed schema validates valid/invalid envelopes and rejects unknown fields; dependency diff is test-only." + }, + { + "id": "F1", + "title": "Add shared V1 request/response conformance fixture matrix", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "S1" + ], + "write_set": [ + "tests/fixtures/query_ir_v1.json", + "__test__/query_ir_schema.test.mjs" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "node --test __test__/query_ir_schema.test.mjs" + ], + "notes": "Cross-check field closure, operation bounds, capability defaults, and unsupported selectors against the accepted spec and current runtime. Do not invent limits or defaults; if the spec/source conflict, stop for owner review before freezing the schema.", + "exit": "Fixtures cover each supported operation and explicit unsupported/rejection cases; all fixtures validate against the frozen schema." + }, + { + "id": "C0", + "title": "Characterize core executor and budget behavior with contract tests", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "F1" + ], + "write_set": [ + "tests/query_ir_tests.rs", + "tests/wave_d_budget_tests.rs" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "cargo test --locked --no-default-features --test query_ir_tests --test wave_d_budget_tests" + ], + "notes": "Characterize observed max_k/max_depth, budgets, capability output, and core typed-error behavior without changing production code. Treat observed values as non-normative until reconciled with the accepted contract.", + "merge_barrier": "C0 and C1 form one candidate. Never merge a deliberately RED-only test stage.", + "exit": "Acceptance tests expose any contract gap without changing production behavior." + }, + { + "id": "C1", + "title": "Apply minimal core corrections only for verified C0 failures", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "C0" + ], + "write_set": [ + "src/lib.rs", + ".brain/rca/RCA--W1-Typed-Query-IR-Conformance.md" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "cargo test --locked --no-default-features --test query_ir_tests --test wave_d_budget_tests", + "cargo fmt --all -- --check" + ], + "exit": "Core contract tests pass; every behavior change has an evidence-backed RCA and remains within accepted V1." + }, + { + "id": "H1", + "title": "Verify and close HQL compatibility mapping without grammar expansion", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "C1" + ], + "write_set": [ + "tests/hql_p0_tests.rs", + "tests/hql_collection_tests.rs", + "tests/hql_cypher_tests.rs", + "tests/wave_e_context_tests.rs" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "cargo test --locked --no-default-features --test hql_p0_tests --test hql_collection_tests --test hql_cypher_tests --test wave_e_context_tests" + ], + "exit": "Existing HQL supported paths preserve semantics; legacy fallback behavior remains intact." + }, + { + "id": "R1", + "title": "Verify REST request/result/error-envelope conformance", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "C1" + ], + "write_set": [ + "src/router.rs", + "tests/rest_api_tests.rs", + "tests/wave_e_rest_tests.rs" + ], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "cargo check --locked --no-default-features --features bins --bin genesis-db-server", + "cargo test --locked --no-default-features --test rest_api_tests --test wave_e_rest_tests" + ], + "notes": "Characterize core-to-REST mappings (including beyond_horizon) in shared fixtures first; freeze only contract-required mappings and do not guess transport status/error semantics.", + "exit": "REST matches the accepted schema, capability declarations, typed failures, and core results." + }, + { + "id": "N1", + "title": "Verify N-API and TypeScript conformance after HQL/REST baselines", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "H1", + "R1" + ], + "write_set": [ + "index.d.ts", + "index.js", + "__test__/query_ir.test.mjs", + "tests/napi_rest_parity_tests.rs", + "scripts/check-dts-freshness.mjs", + "src/lib.rs" + ], + "conditional_write_set": { + "paths": [ + "src/lib.rs" + ], + "when": "Only if N-API binding behavior is proven missing; after C1, H1, and R1, with affected gates rerun." + }, + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "cargo test --locked --no-default-features --test napi_rest_parity_tests", + "npm run build", + "node scripts/check-dts-freshness.mjs ", + "node --test __test__/query_ir.test.mjs" + ], + "notes": "Preserve the candidate's committed index.d.ts/index.js before the addon build, run the build in an isolated copy, compare preserved/generated directories with the existing freshness checker, and inspect any generated changes before integrating them.", + "exit": "N-API results/errors match REST and TypeScript declarations accurately describe discriminated operation/result envelopes; generated artifacts are freshness-checked." + }, + { + "id": "X1", + "title": "Audit declared SDK and MCP consumer support (evidence-only)", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "F1" + ], + "write_set": [], + "worker_model": "gpt-6-luna", + "reasoning_effort": "max", + "verify": [ + "(genesisdb-python) python -m unittest discover -s tests -p test_client_contract.py", + "(genesisdb-go) go test ./...", + "(repository root) node --test __test__/mcp.test.mjs" + ], + "exit": "Record supported, partial, unsupported, and NOT_RUN per consumer; do not add adapter scope or modify SDK/MCP files in this task." + }, + { + "id": "V", + "title": "Integrated Verify Gate on one immutable candidate SHA", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "H1", + "R1", + "N1", + "X1", + "D1" + ], + "write_set": [], + "verifier": "Codex coordinator; deterministic commands and captured exit codes", + "verify": [ + "node --test __test__/query_ir_schema.test.mjs", + "npm run build", + "cargo test --locked --no-default-features", + "npm test", + "cargo clippy --no-default-features --all-targets -- -D warnings", + "cargo clippy --all-targets -- -D warnings", + "cargo fmt --all -- --check", + "node scripts/check-dts-freshness.mjs ", + "npm run docs:validate", + "git diff --check" + ], + "exit": "All required gates pass on the same candidate SHA; every skip/failure is explained and cannot be promoted to PASS." + }, + { + "id": "RV", + "title": "Independent architecture and diff Review Gate", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "V" + ], + "write_set": [], + "reviewer_model": "gpt-6-astra", + "reasoning_effort": "max", + "read_only": true, + "verify": [ + "Review changed files, acceptance mapping, task write sets, and exact Verify evidence" + ], + "exit": "Astra returns PASS or explicit findings; any changed candidate invalidates affected Verify and Review evidence." + }, + { + "id": "D1", + "title": "Reconcile final implementation and evidence into canonical docs", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "H1", + "R1", + "N1", + "X1" + ], + "write_set": [ + "docs/MASTER_PLAN.md", + "docs/SPEC--GENESISDB-TYPED-QUERY-IR-V1.md", + "queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json", + "queue/QUERY_IR_W1_PROJECT_GRAPH.json" + ], + "worker": "Codex coordinator; Luna may draft bounded docs after approval", + "verify": [ + "npm run docs:validate", + "git diff --check" + ], + "exit": "Status claims cite exact source SHA and evidence; unsupported and unrun surfaces remain explicit, and the overall spec stays partial until every accepted gate is satisfied." + }, + { + "id": "FG", + "title": "Final Gate: acceptance, provenance, scope, and merge readiness", + "status": "proposed", + "ready": false, + "dispatch_authorized": false, + "deps": [ + "RV" + ], + "write_set": [], + "final_owner": "Codex coordinator", + "verify": [ + "Recheck acceptance criteria, immutable candidate SHA, Verify PASS, Astra Review PASS, docs consistency, and merge-order compliance" + ], + "exit": "PASS only when all required evidence is present; does not itself grant additional code scope, push, merge, release, or deployment authority." + } + ], + "verification_commands": { + "focused_core": "cargo test --locked --no-default-features --test query_ir_tests --test wave_d_budget_tests", + "focused_hql": "cargo test --locked --no-default-features --test hql_p0_tests --test hql_collection_tests --test hql_cypher_tests --test wave_e_context_tests", + "rest_build": "cargo check --locked --no-default-features --features bins --bin genesis-db-server", + "focused_rest": "cargo test --locked --no-default-features --test rest_api_tests --test wave_e_rest_tests", + "focused_napi": "cargo test --locked --no-default-features --test napi_rest_parity_tests", + "schema_and_fixtures": "node --test __test__/query_ir_schema.test.mjs", + "node_query_ir": "node --test __test__/query_ir.test.mjs", + "native_addon": "npm run build", + "napi_freshness": "node scripts/check-dts-freshness.mjs ", + "strict_clippy_no_default": "cargo clippy --no-default-features --all-targets -- -D warnings", + "strict_clippy_default": "cargo clippy --all-targets -- -D warnings", + "full_rust": "cargo test --locked --no-default-features", + "full_node": "npm test", + "format": "cargo fmt --all -- --check", + "docs": "npm run docs:validate", + "diff": "git diff --check" + }, + "evidence_limits": [ + "No power-loss/device/release/deployment/production claim follows from local tests.", + "A source implementation or passing focused test does not establish every V1 capability.", + "No SDK/MCP support is assumed without consumer-specific evidence." + ] +} diff --git a/queue/QUERY_IR_W1_PROJECT_GRAPH.json b/queue/QUERY_IR_W1_PROJECT_GRAPH.json new file mode 100644 index 00000000..c1792855 --- /dev/null +++ b/queue/QUERY_IR_W1_PROJECT_GRAPH.json @@ -0,0 +1,340 @@ +{ + "id": "GRAPH-QUERY-IR-W1", + "type": "execution_dag", + "title": "Typed Query IR W1 conflict-free execution and merge graph", + "version": "0.1.0", + "status": "proposed", + "source_of_truth": false, + "ready": false, + "dispatch_authorized": false, + "created_at": "2026-10-06T18:28:36+07:00", + "updated_at": "2026-10-06T18:28:36+07:00", + "source_sha": "987bf32507af6e1f9cc612385db093b4358996ed", + "queue": "queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json", + "nodes": [ + { + "id": "P0", + "depends_on": [], + "write_set": [ + "docs/SPEC--GENESISDB-G3-EXACT-ORACLE-AND-RECOVERY.md", + "docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html", + ".brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md", + "docs/MASTER_PLAN.md", + "queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json", + "queue/QUERY_IR_W1_PROJECT_GRAPH.json" + ], + "gate": false + }, + { + "id": "G0", + "depends_on": [ + "P0" + ], + "write_set": [], + "gate": true + }, + { + "id": "D0", + "depends_on": [ + "G0" + ], + "write_set": [], + "gate": true + }, + { + "id": "S1", + "depends_on": [ + "D0" + ], + "write_set": [ + "docs/contracts/query-ir.v1.schema.json", + "package.json", + "package-lock.json", + "__test__/query_ir_schema.test.mjs" + ], + "gate": false + }, + { + "id": "F1", + "depends_on": [ + "S1" + ], + "write_set": [ + "tests/fixtures/query_ir_v1.json", + "__test__/query_ir_schema.test.mjs" + ], + "gate": false + }, + { + "id": "C0", + "depends_on": [ + "F1" + ], + "write_set": [ + "tests/query_ir_tests.rs", + "tests/wave_d_budget_tests.rs" + ], + "gate": false + }, + { + "id": "C1", + "depends_on": [ + "C0" + ], + "write_set": [ + "src/lib.rs", + ".brain/rca/RCA--W1-Typed-Query-IR-Conformance.md" + ], + "gate": false + }, + { + "id": "H1", + "depends_on": [ + "C1" + ], + "write_set": [ + "tests/hql_p0_tests.rs", + "tests/hql_collection_tests.rs", + "tests/hql_cypher_tests.rs", + "tests/wave_e_context_tests.rs" + ], + "gate": false + }, + { + "id": "R1", + "depends_on": [ + "C1" + ], + "write_set": [ + "src/router.rs", + "tests/rest_api_tests.rs", + "tests/wave_e_rest_tests.rs" + ], + "gate": false + }, + { + "id": "N1", + "depends_on": [ + "H1", + "R1" + ], + "write_set": [ + "index.d.ts", + "index.js", + "__test__/query_ir.test.mjs", + "tests/napi_rest_parity_tests.rs", + "scripts/check-dts-freshness.mjs", + "src/lib.rs" + ], + "gate": false + }, + { + "id": "X1", + "depends_on": [ + "F1" + ], + "write_set": [], + "gate": false + }, + { + "id": "V", + "depends_on": [ + "H1", + "R1", + "N1", + "X1", + "D1" + ], + "write_set": [], + "gate": true + }, + { + "id": "RV", + "depends_on": [ + "V" + ], + "write_set": [], + "gate": true + }, + { + "id": "D1", + "depends_on": [ + "H1", + "R1", + "N1", + "X1" + ], + "write_set": [ + "docs/MASTER_PLAN.md", + "docs/SPEC--GENESISDB-TYPED-QUERY-IR-V1.md", + "queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json", + "queue/QUERY_IR_W1_PROJECT_GRAPH.json" + ], + "gate": false + }, + { + "id": "FG", + "depends_on": [ + "RV" + ], + "write_set": [], + "gate": true + } + ], + "edges": [ + { + "from": "P0", + "to": "G0" + }, + { + "from": "G0", + "to": "D0" + }, + { + "from": "D0", + "to": "S1" + }, + { + "from": "S1", + "to": "F1" + }, + { + "from": "F1", + "to": "C0" + }, + { + "from": "C0", + "to": "C1" + }, + { + "from": "C1", + "to": "H1" + }, + { + "from": "C1", + "to": "R1" + }, + { + "from": "H1", + "to": "N1" + }, + { + "from": "R1", + "to": "N1" + }, + { + "from": "F1", + "to": "X1" + }, + { + "from": "H1", + "to": "D1" + }, + { + "from": "R1", + "to": "D1" + }, + { + "from": "N1", + "to": "D1" + }, + { + "from": "H1", + "to": "V" + }, + { + "from": "R1", + "to": "V" + }, + { + "from": "N1", + "to": "V" + }, + { + "from": "X1", + "to": "D1" + }, + { + "from": "X1", + "to": "V" + }, + { + "from": "D1", + "to": "V" + }, + { + "from": "V", + "to": "RV" + }, + { + "from": "RV", + "to": "FG" + } + ], + "parallel_sets": [ + { + "after": "C1", + "tasks": [ + "H1", + "R1", + "X1" + ], + "safe_because": "H1 and R1 have disjoint file write sets; X1 has an empty write set and is evidence-only." + } + ], + "merge_order": [ + [ + "P0" + ], + [ + "G0" + ], + [ + "D0" + ], + [ + "S1" + ], + [ + "F1" + ], + [ + "C0", + "C1" + ], + [ + "H1", + "R1", + "X1" + ], + [ + "N1" + ], + [ + "D1" + ], + [ + "V" + ], + [ + "RV" + ], + [ + "FG" + ] + ], + "merge_order_notes": "G0 plan acceptance and D0 dispatch authorization are separate owner gates. H1 and R1 may execute in parallel but their code merges are sequential (H1 then R1); X1 is evidence-only, is not merged, and must complete before D1 and V.", + "atomic_merge_groups": [ + [ + "C0", + "C1" + ] + ], + "gates": { + "verify": "V — deterministic commands, same candidate SHA", + "review": "RV — independent gpt-6-astra Max, read-only", + "final": "FG — Codex evidence/scope/provenance check", + "owner_authority": "G0 plan approval and D0 separate implementation dispatch approval" + }, + "failure_policy": "Any change after V invalidates dependent evidence. Fixes return to the owning task, then rerun affected downstream gates; failed gates never authorize merge." +}