Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 25 additions & 4 deletions .brain/rca/RCA--G3-WAL-ONLY-RECOVERY-PROOF-GAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,9 @@ without materialized snapshot or projection files.
with the recovered frontier.
- Both paths compare pre-reopen and post-reopen query results. Those equality
checks can pass if a materialized file was not removed.
- The focused target passes 2/2 on the current mainline; that is baseline
result-comparison evidence only.
- At pre-fix baseline `aed35b7f5dee320a703b41db035d30daa71139ee`, the focused
target passed 2/2; this was result-comparison evidence only and predates the
merged correction.

## Root Cause

Expand Down Expand Up @@ -53,8 +54,8 @@ therefore mistaken for proof of the recovery path.
5. Keep this correction test-only in tests/g3_oracle_differential_tests.rs,
then run the focused target and its specified G1/G2/crash regression matrix.
6. Report WAL-only recovery as NOT_PROVEN until these assertions are
implemented and pass. Do not promote this test result to hosted CI,
power-loss, release, deployment, or broad P7 evidence.
implemented and pass; after they pass, claim only the bounded test proof.
Do not promote it to power-loss, release, deployment, or broad P7 evidence.

## Implementation follow-up — CI Clippy failure (2026-10-06)

Expand Down Expand Up @@ -91,9 +92,29 @@ not exercise the same lint acceptance check as CI.
`cargo clippy --no-default-features --all-targets -- -D warnings` and
`cargo clippy --all-targets -- -D warnings`.

## Resolution — PR #217 merged 2026-10-06

The test-evidence root cause is resolved for the bounded `g3.oracle.v1` proof.
The merged correction makes materialized-file removal fail closed, verifies
those files are absent before reopen, and checks that the recovered stable
frontier covers the final pre-close frontier. Exact query/oracle comparisons
remain in place.

PR #217 head `9221b74e7dd81c350e099ac6b4a034810971d9b0` merged as
`987bf32507af6e1f9cc612385db093b4358996ed`. Hosted Tests, Security Audit,
GenesisRAG17 Linux worker, Performance Audit, and Package Manager Consumer
checks passed. The Linux worker had 26 passes, 0 failures, and 6 skips because
the pinned ONNX model snapshot was absent. The former Clippy issue was fixed
with `std::io::Error::other(...)` and the hosted checks passed.

Closure is limited to the named test proof and CI checks. Physical power-loss,
mobile/device, migration, release, deployment, and production acceptance are
not established by this RCA resolution.

## Version Diff

| From | To | Change |
|---|---|---|
| none | 1.0.0 | Record the G3 WAL-only recovery test-evidence root cause and bounded prevention criteria. |
| 1.0.0 | 1.0.1 | Record the PR #217 Clippy failure, evidence, root cause, and lint-gate prevention. |
| 1.0.1 | 1.0.2 | Record resolution of the bounded G3 test-evidence gap on merged PR #217, including hosted checks and skipped-test limits. |
51 changes: 31 additions & 20 deletions docs/MASTER_PLAN.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
status: current
version: "0.2.1"
updated: "2026-08-14"
version: "0.2.2"
updated: "2026-10-06"
owner: "Boss (Founder / Product Authority)"
approval: "Approved in-session 2026-08-14"
---
Expand Down Expand Up @@ -36,7 +36,7 @@ adapter as implemented. The governing decisions are:
| HQL P0 correctness work | Implemented and merged on `main`; retained as compatibility baseline. |
| HQL P1/P2/P3 expansion | Deferred; not required for the primary public contract. |
| Typed Query IR ADR/spec | Accepted by owner on 2026-08-14. |
| Typed Query IR executor/API | Partial: `search` and `traverse` implemented across core, REST and N-API; remaining operation kinds planned. |
| Typed Query IR executor/API | Partial: source implementations exist for `search`, `traverse`, `match_path`, and target-ID `context`; W1 conformance is not freshly verified end-to-end. `relational_named_query` remains unsupported. |
| NL-to-Query-IR adapter | Planned outside the engine; not implemented. |
| Engine package/release | Remains a productization gate; acceptance requires registry/install evidence. |

Expand All @@ -62,7 +62,7 @@ model/provider work cannot block the database engine or leak into its core.
| Wave | Scope | Deliverable | Exit criteria |
|---|---|---|---|
| W0 | Architecture boundary | Accepted ADR/spec, registry/C4/parent-doc alignment, this plan | Documentation validators pass; implementation status remains truthful. |
| W1 | Typed Query IR | Closed V1 schema, Rust typed executor, N-API/REST bindings, capability reporting, HQL mapping | Search/traverse vertical slice passes core, REST and N-API parity; HQL compatibility fixtures pass. |
| W1 | Typed Query IR contract/conformance closure | Freeze the standalone V1 schema and fixtures; characterize existing core behavior; close HQL, REST, and N-API parity gaps for supported operations | Shared schema/fixture gates pass; supported operations meet the accepted V1 contract across declared surfaces; unsupported operations fail closed. |
| W2 | Publish engine | Release tag/matrix, platform prebuilds, package docs/security/version alignment | Clean-machine install and smoke evidence; no path-dependent dependency. |
| GATE-DEMAND-1 | Demand evidence | First-10-external-installs record over an owner-defined measurement window | Owner records proceed, pivot or stop before expensive adapter/channel work. |
| W3 | External NL adapter | Separate provider-neutral adapter package producing `QueryRequestV1`; MCP prefers typed operations | Schema/capability/auth rejection and ambiguous-intent fail-closed tests pass; engine has no LLM dependency. |
Expand All @@ -79,19 +79,23 @@ model/provider work cannot block the database engine or leak into its core.
| W3 NL adapter | `TQIR-009`, ADR agent-boundary rules | Outside engine, schema-validated and fail closed. |
| W2/W4 distribution | `GB-SRS-NFR-005`, `GB-SRS-NFR-007..008` | Installability, compatibility and security evidence. |

## 5. First implementation slice (W1)
## 5. W1 contract/conformance closure

The first slice is deliberately bounded:
W1 is a verification-and-gap-closure wave over the current Typed Query IR V1
implementation, not a rewrite of the executor or a claim that all reserved
operations are implemented. The current spec remains `partial`. The proposed
queue and execution graph are `queue/QUERY_IR_W1_IMPLEMENTATION_QUEUE.json` and
`queue/QUERY_IR_W1_PROJECT_GRAPH.json`; both are non-dispatchable until the
owner reviews and accepts the W1 plan and separately authorizes implementation.

1. Freeze JSON Schema plus Rust request/result enums for `search` and `traverse`.
2. Add RED tests for validation, unsupported versions, bounds and collection mismatch.
3. Implement one typed core dispatcher over existing storage methods.
4. Expose N-API and REST routes with equivalent envelopes.
5. Map HQL `SEARCH` and `TRAVERSE` to the typed dispatcher and run parity fixtures.
6. Report operation support through capability/version output.

`match_path`, `context` and `relational_named_query` are reserved V1 operation kinds but require their
own closed schemas and acceptance tests before being reported as implemented.
The proposed sequence freezes a standalone closed V1 schema and shared fixtures,
characterizes current behavior, then closes only evidence-backed conformance
gaps across core, HQL compatibility, REST, and N-API. Existing `search`,
`traverse`, `match_path`, and target-ID `context` behavior must be measured
against the accepted schema and capability contract before any status is
promoted. `relational_named_query` is not implemented and is out of scope for
this W1 queue. Existing HQL fallback behavior is preserved; W1 does not expand
or remove HQL.

## 6. Milestones

Expand All @@ -113,14 +117,17 @@ own closed schemas and acceptance tests before being reported as implemented.
| R3 | NL model emits valid-looking unauthorized queries | 4 | 5 | 20 | Treat output as untrusted; schema, capability and caller-policy validation; fail closed. |
| R4 | V1 becomes an unrestricted JSON escape hatch | 3 | 5 | 15 | Closed discriminated types; reject unknown fields; no generic payload. |
| R5 | Cross-surface contract version drift | 3 | 4 | 12 | Shared fixtures and capability-version conformance in CI. |
| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to search/traverse vertical slice; reserve other operations. |
| R6 | Query-contract work delays installability indefinitely | 3 | 4 | 12 | Limit W1 to conformance closure for existing supported operations; exclude `relational_named_query` and require explicit scope review for additions. |
| R7 | No external demand after publish | 3 | 5 | 15 | Preserve GATE-DEMAND-1 before expensive adapter/channel work. |
| R8 | Graphiti requires broader Cypher semantics | 3 | 3 | 9 | Inspect upstream contract before W5; adapt typed IR rather than expanding HQL automatically. |

## 8. Scope boundaries

In scope now: architecture docs, V1 contract, master-plan alignment and the completed W1
`search`/`traverse` vertical slice. Remaining V1 operations require separate slices.
In scope now: architecture/docs reconciliation and a proposed W1 execution plan.
The plan targets contract/conformance evidence for existing `search`, `traverse`,
`match_path`, and target-ID `context` implementations. This document approval
does not authorize W1 code changes. `relational_named_query` and all other
unsupported modes remain outside the proposed queue.

Out of scope until its wave is approved/executed:

Expand All @@ -145,13 +152,17 @@ The previous `33_TASK_BREAKDOWN.md`, `36_TASK_EXECUTION_ORDER.md`, `PHASE_6_REVI
`queue/IMPLEMENTATION_QUEUE.json` and `queue/PROJECT_GRAPH.json` describe the superseded HQL-first
sequence. They are retained as historical evidence with `source_of_truth: false` where machine-readable.

The next planning action is to decompose W1 from the accepted Query IR V1 requirements and submit the
replacement queue/graph for review. Until that happens, no old `ready: true` flag authorizes dispatch.
The proposed W1 queue/graph are review artifacts only: `status: proposed`,
`source_of_truth: false`, `ready: false`, and `dispatch_authorized: false`.
The superseded HQL-first queue and graph remain unchanged. No task may dispatch
until the owner accepts the replacement plan and separately authorizes W1
implementation; historical `ready: true` flags confer no authority.

## CHANGELOG

| Version | Date | Status | Summary | Commit Hash | Agent |
|---|---|---|---|---|---|
| 0.2.0 | 2026-08-14 | current | Approved Typed Query IR as pre-publish contract, retained HQL compatibility and moved NL conversion to an external post-publish adapter wave. | working-tree | ATHER |
| 0.2.1 | 2026-08-14 | current | Recorded completion of the W1 search/traverse vertical slice across core, REST and N-API while retaining remaining V1 operations as planned. | working-tree | ATHER |
| 0.2.2 | 2026-10-06 | current | Reconciled W1 to existing Query IR operation implementations; reframed the next wave as non-dispatchable conformance closure, excluding relational_named_query. | working-tree | Codex |
| 0.1.0 | 2026-07-07 | superseded | Initial engine-wedge distribution plan centered on HQL P0 and four distribution waves. | historical | ATHER |
10 changes: 5 additions & 5 deletions docs/P7.1-G3-RECOVERY-EXECUTION-DAG.html
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ <h1>G3 recovery proof · execution dependencies</h1>
<div class="diagram-container">
<svg viewBox="0 0 960 600" xmlns="http://www.w3.org/2000/svg" role="img" aria-labelledby="p71-g3-recovery-title p71-g3-recovery-desc">
<title id="p71-g3-recovery-title">G3 recovery proof execution dependencies</title>
<desc id="p71-g3-recovery-desc">Four ranked dependency layers show the pending model and code authorization prerequisite, one-file test worker, parallel Verify and Review gates, and a Final Gate that does not authorize merge.</desc>
<desc id="p71-g3-recovery-desc">Four ranked dependency layers show the selected gpt-6-luna Max worker, merged G3 test correction, Verify and Review gates, and a Final Gate. PR 217 is merged; the diagram records evidence and does not authorize a separate merge.</desc>
<defs>
<marker id="arrow" markerWidth="8" markerHeight="6" refX="7" refY="3" orient="auto"><polygon points="0 0, 8 3, 0 6" fill="#4f5d75"/></marker>
<marker id="arrow-accent" markerWidth="8" markerHeight="6" refX="7" refY="3" orient="auto"><polygon points="0 0, 8 3, 0 6" fill="#eb6c36"/></marker>
Expand Down Expand Up @@ -129,7 +129,7 @@ <h1>G3 recovery proof · execution dependencies</h1>
<text x="426" y="335" fill="#2d3142" font-size="7" font-family="'Geist Mono', monospace" text-anchor="middle" letter-spacing="0.08em">WORKER</text>
<rect x="524" y="328" width="28" height="12" rx="2" fill="transparent" stroke="rgba(45,49,66,0.40)" stroke-width="0.8"/>
<text x="538" y="337" fill="#2d3142" font-size="8" font-family="'Geist Mono', monospace" text-anchor="middle">2 IN</text>
<text x="480" y="354" fill="#2d3142" font-size="12" font-weight="600" font-family="'Geist', sans-serif" text-anchor="middle">Test-only Worker</text>
<text x="480" y="354" fill="#2d3142" font-size="12" font-weight="600" font-family="'Geist', sans-serif" text-anchor="middle">G3 Test-only Worker</text>
<text x="480" y="370" fill="#4f5d75" font-size="9" font-family="'Geist Mono', monospace" text-anchor="middle">one source test file</text>

<!-- Authorization prerequisite (leaf) -->
Expand All @@ -139,8 +139,8 @@ <h1>G3 recovery proof · execution dependencies</h1>
<text x="422" y="455" fill="#2d3142" font-size="7" font-family="'Geist Mono', monospace" text-anchor="middle" letter-spacing="0.08em">GATE</text>
<rect x="524" y="448" width="28" height="12" rx="2" fill="transparent" stroke="rgba(45,49,66,0.40)" stroke-width="0.8"/>
<text x="538" y="457" fill="#2d3142" font-size="8" font-family="'Geist Mono', monospace" text-anchor="middle">1 IN</text>
<text x="480" y="474" fill="#2d3142" font-size="12" font-weight="600" font-family="'Geist', sans-serif" text-anchor="middle">Model + Code Gate</text>
<text x="480" y="490" fill="#4f5d75" font-size="9" font-family="'Geist Mono', monospace" text-anchor="middle">docs approved · choice pending</text>
<text x="480" y="474" fill="#2d3142" font-size="12" font-weight="600" font-family="'Geist', sans-serif" text-anchor="middle">Model + Scope Gate</text>
<text x="480" y="490" fill="#4f5d75" font-size="9" font-family="'Geist Mono', monospace" text-anchor="middle">gpt-6-luna Max · authorization cleared</text>

<line x1="40" y1="524" x2="920" y2="524" stroke="rgba(45,49,66,0.10)" stroke-width="0.8"/>
<text x="40" y="540" fill="#4f5d75" font-size="8" font-family="'Geist Mono', monospace" letter-spacing="0.18em">LEGEND</text>
Expand All @@ -155,7 +155,7 @@ <h1>G3 recovery proof · execution dependencies</h1>
</svg>
</div>

<p class="note"><strong>Current hold:</strong> documentation is approved, but the requested gpt-5.6-luna Max effort is not advertised here; no substitute is selected. No source worker starts until a supported model and code-scope authorization are explicit. A failed gate stops the candidate; any corrected candidate must rerun Verify, Review, and Final. Final PASS does not authorize commit, push, or merge.</p>
<p class="note"><strong>G3 status:</strong> PR #217 (head <code>9221b74</code>, merge <code>987bf32</code>) is merged. Hosted checks passed; the Linux worker reported 26 passed, 0 failed, and 6 skipped because the pinned ONNX model snapshot was absent. The selected <code>gpt-6-luna Max</code> worker choice and scoped authorization are historical workflow context, not a claim about which runtime executed CI. Power-loss hardware, mobile/device, release, deployment, and production acceptance remain unverified. A failed gate stops its candidate; corrections rerun Verify, Review, and Final. This evidence does not authorize a separate commit, push, or merge.</p>
</main>
</body>
</html>
Loading
Loading