diff --git a/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md b/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md index 9f7ce802..b4194c05 100644 --- a/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md +++ b/.brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md @@ -23,8 +23,9 @@ without materialized snapshot or projection files. with the recovered frontier. - Both paths compare pre-reopen and post-reopen query results. Those equality checks can pass if a materialized file was not removed. -- The focused target passes 2/2 on the current mainline; that is baseline - result-comparison evidence only. +- At pre-fix baseline `aed35b7f5dee320a703b41db035d30daa71139ee`, the focused + target passed 2/2; this was result-comparison evidence only and predates the + merged correction. ## Root Cause @@ -53,8 +54,8 @@ therefore mistaken for proof of the recovery path. 5. Keep this correction test-only in tests/g3_oracle_differential_tests.rs, then run the focused target and its specified G1/G2/crash regression matrix. 6. Report WAL-only recovery as NOT_PROVEN until these assertions are - implemented and pass. Do not promote this test result to hosted CI, - power-loss, release, deployment, or broad P7 evidence. + implemented and pass; after they pass, claim only the bounded test proof. + Do not promote it to power-loss, release, deployment, or broad P7 evidence. ## Implementation follow-up — CI Clippy failure (2026-10-06) @@ -91,9 +92,29 @@ not exercise the same lint acceptance check as CI. `cargo clippy --no-default-features --all-targets -- -D warnings` and `cargo clippy --all-targets -- -D warnings`. +## Resolution — PR #217 merged 2026-10-06 + +The test-evidence root cause is resolved for the bounded `g3.oracle.v1` proof. +The merged correction makes materialized-file removal fail closed, verifies +those files are absent before reopen, and checks that the recovered stable +frontier covers the final pre-close frontier. Exact query/oracle comparisons +remain in place. + +PR #217 head `9221b74e7dd81c350e099ac6b4a034810971d9b0` merged as +`987bf32507af6e1f9cc612385db093b4358996ed`. Hosted Tests, Security Audit, +GenesisRAG17 Linux worker, Performance Audit, and Package Manager Consumer +checks passed. The Linux worker had 26 passes, 0 failures, and 6 skips because +the pinned ONNX model snapshot was absent. The former Clippy issue was fixed +with `std::io::Error::other(...)` and the hosted checks passed. + +Closure is limited to the named test proof and CI checks. Physical power-loss, +mobile/device, migration, release, deployment, and production acceptance are +not established by this RCA resolution. + ## Version Diff | From | To | Change | |---|---|---| | none | 1.0.0 | Record the G3 WAL-only recovery test-evidence root cause and bounded prevention criteria. | | 1.0.0 | 1.0.1 | Record the PR #217 Clippy failure, evidence, root cause, and lint-gate prevention. | +| 1.0.1 | 1.0.2 | Record resolution of the bounded G3 test-evidence gap on merged PR #217, including hosted checks and skipped-test limits. | diff --git a/docs/MASTER_PLAN.md b/docs/MASTER_PLAN.md index 97215172..39966911 100644 --- a/docs/MASTER_PLAN.md +++ b/docs/MASTER_PLAN.md @@ -1,7 +1,7 @@ --- status: current -version: "0.2.1" -updated: "2026-08-14" +version: "0.2.2" +updated: "2026-10-06" owner: "Boss (Founder / Product Authority)" approval: "Approved in-session 2026-08-14" --- @@ -36,7 +36,7 @@ adapter as implemented. The governing decisions are: | HQL P0 correctness work | Implemented and merged on `main`; retained as compatibility baseline. | | HQL P1/P2/P3 expansion | Deferred; not required for the primary public contract. | | Typed Query IR ADR/spec | Accepted by owner on 2026-08-14. | -| Typed Query IR executor/API | Partial: `search` and `traverse` implemented across core, REST and N-API; remaining operation kinds planned. | +| Typed Query IR executor/API | Partial: source implementations exist for `search`, `traverse`, `match_path`, and target-ID `context`; W1 conformance is not freshly verified end-to-end. `relational_named_query` remains unsupported. | | NL-to-Query-IR adapter | Planned outside the engine; not implemented. | | Engine package/release | Remains a productization gate; acceptance requires registry/install evidence. | @@ -62,7 +62,7 @@ model/provider work cannot block the database engine or leak into its core. | Wave | Scope | Deliverable | Exit criteria | |---|---|---|---| | W0 | Architecture boundary | Accepted ADR/spec, registry/C4/parent-doc alignment, this plan | Documentation validators pass; implementation status remains truthful. | -| W1 | Typed Query IR | Closed V1 schema, Rust typed executor, N-API/REST bindings, capability reporting, HQL mapping | Search/traverse vertical slice passes core, REST and N-API parity; HQL compatibility fixtures pass. | +| W1 | Typed Query IR contract/conformance closure | Freeze the standalone V1 schema and fixtures; characterize existing core behavior; close HQL, REST, and N-API parity gaps for supported operations | Shared schema/fixture gates pass; supported operations meet the accepted V1 contract across declared surfaces; unsupported operations fail closed. | | W2 | Publish engine | Release tag/matrix, platform prebuilds, package docs/security/version alignment | Clean-machine install and smoke evidence; no path-dependent dependency. | | GATE-DEMAND-1 | Demand evidence | First-10-external-installs record over an owner-defined measurement window | Owner records proceed, pivot or stop before expensive adapter/channel work. | | W3 | External NL adapter | Separate provider-neutral adapter package producing `QueryRequestV1`; MCP prefers typed operations | Schema/capability/auth rejection and ambiguous-intent fail-closed tests pass; engine has no LLM dependency. | @@ -79,19 +79,23 @@ model/provider work cannot block the database engine or leak into its core. | W3 NL adapter | `TQIR-009`, ADR agent-boundary rules | Outside engine, schema-validated and fail closed. | | W2/W4 distribution | `GB-SRS-NFR-005`, `GB-SRS-NFR-007..008` | Installability, compatibility and security evidence. | -## 5. First implementation slice (W1) +## 5. W1 contract/conformance closure -The first slice is deliberately bounded: +W1 is a verification-and-gap-closure wave over the current Typed Query IR V1 +implementation, not a rewrite of the executor or a claim that all reserved +operations are implemented. The current spec remains `partial`. The proposed +queue and execution graph are `queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json` and +`queue/QUERY_IR_W1_PROJECT_GRAPH.json`; both are non-dispatchable until the +owner reviews and accepts the W1 plan and separately authorizes implementation. -1. Freeze JSON Schema plus Rust request/result enums for `search` and `traverse`. -2. Add RED tests for validation, unsupported versions, bounds and collection mismatch. -3. Implement one typed core dispatcher over existing storage methods. -4. Expose N-API and REST routes with equivalent envelopes. -5. Map HQL `SEARCH` and `TRAVERSE` to the typed dispatcher and run parity fixtures. -6. Report operation support through capability/version output. - -`match_path`, `context` and `relational_named_query` are reserved V1 operation kinds but require their -own closed schemas and acceptance tests before being reported as implemented. +The proposed sequence freezes a standalone closed V1 schema and shared fixtures, +characterizes current behavior, then closes only evidence-backed conformance +gaps across core, HQL compatibility, REST, and N-API. Existing `search`, +`traverse`, `match_path`, and target-ID `context` behavior must be measured +against the accepted schema and capability contract before any status is +promoted. `relational_named_query` is not implemented and is out of scope for +this W1 queue. Existing HQL fallback behavior is preserved; W1 does not expand +or remove HQL. ## 6. Milestones @@ -113,14 +117,17 @@ own closed schemas and acceptance tests before being reported as implemented. | R3 | NL model emits valid-looking unauthorized queries | 4 | 5 | 20 | Treat output as untrusted; schema, capability and caller-policy validation; fail closed. | | R4 | V1 becomes an unrestricted JSON escape hatch | 3 | 5 | 15 | Closed discriminated types; reject unknown fields; no generic payload. | | R5 | Cross-surface contract version drift | 3 | 4 | 12 | Shared fixtures and capability-version conformance in CI. | -| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to search/traverse vertical slice; reserve other operations. | +| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to conformance closure for existing supported operations; exclude `relational_named_query` and require explicit scope review for additions. | | R7 | No external demand after publish | 3 | 5 | 15 | Preserve GATE-DEMAND-1 before expensive adapter/channel work. | | R8 | Graphiti requires broader Cypher semantics | 3 | 3 | 9 | Inspect upstream contract before W5; adapt typed IR rather than expanding HQL automatically. | ## 8. Scope boundaries -In scope now: architecture docs, V1 contract, master-plan alignment and the completed W1 -`search`/`traverse` vertical slice. Remaining V1 operations require separate slices. +In scope now: architecture/docs reconciliation and a proposed W1 execution plan. +The plan targets contract/conformance evidence for existing `search`, `traverse`, +`match_path`, and target-ID `context` implementations. This document approval +does not authorize W1 code changes. `relational_named_query` and all other +unsupported modes remain outside the proposed queue. Out of scope until its wave is approved/executed: @@ -145,8 +152,11 @@ The previous `33_TASK_BREAKDOWN.md`, `36_TASK_EXECUTION_ORDER.md`, `PHASE_6_REVI `queue/IMPLEMENTATION_QUEUE.json` and `queue/PROJECT_GRAPH.json` describe the superseded HQL-first sequence. They are retained as historical evidence with `source_of_truth: false` where machine-readable. -The next planning action is to decompose W1 from the accepted Query IR V1 requirements and submit the -replacement queue/graph for review. Until that happens, no old `ready: true` flag authorizes dispatch. +The proposed W1 queue/graph are review artifacts only: `status: proposed`, +`source_of_truth: false`, `ready: false`, and `dispatch_authorized: false`. +The superseded HQL-first queue and graph remain unchanged. No task may dispatch +until the owner accepts the replacement plan and separately authorizes W1 +implementation; historical `ready: true` flags confer no authority. ## CHANGELOG @@ -154,4 +164,5 @@ replacement queue/graph for review. Until that happens, no old `ready: true` fla |---|---|---|---|---|---| | 0.2.0 | 2026-08-14 | current | Approved Typed Query IR as pre-publish contract, retained HQL compatibility and moved NL conversion to an external post-publish adapter wave. | working-tree | ATHER | | 0.2.1 | 2026-08-14 | current | Recorded completion of the W1 search/traverse vertical slice across core, REST and N-API while retaining remaining V1 operations as planned. | working-tree | ATHER | +| 0.2.2 | 2026-10-06 | current | Reconciled W1 to existing Query IR operation implementations; reframed the next wave as non-dispatchable conformance closure, excluding relational_named_query. | working-tree | Codex | | 0.1.0 | 2026-07-07 | superseded | Initial engine-wedge distribution plan centered on HQL P0 and four distribution waves. | historical | ATHER | diff --git a/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html b/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html index 8dee5f18..0878a436 100644 --- a/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html +++ b/docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html @@ -71,7 +71,7 @@
Current hold: documentation is approved, but the requested gpt-5.6-luna Max effort is not advertised here; no substitute is selected. No source worker starts until a supported model and code-scope authorization are explicit. A failed gate stops the candidate; any corrected candidate must rerun Verify, Review, and Final. Final PASS does not authorize commit, push, or merge.
+G3 status: PR #217 (head 9221b74, merge 987bf32) is merged. Hosted checks passed; the Linux worker reported 26 passed, 0 failed, and 6 skipped because the pinned ONNX model snapshot was absent. The selected gpt-6-luna Max worker choice and scoped authorization are historical workflow context, not a claim about which runtime executed CI. Power-loss hardware, mobile/device, release, deployment, and production acceptance remain unverified. A failed gate stops its candidate; corrections rerun Verify, Review, and Final. This evidence does not authorize a separate commit, push, or merge.