Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:48:10Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 11,
"change": {
"change": "evidence",
"kind": "verification",
"source": "Release baseline shared-clock probe failed its 2x bound: medians at55/601/1203 events 92.517484ms/7.038153041s/12.449723852s; all fixture shape/history/revision assertions passed; exit101",
"reference": "crates/entity-eventlog/tests/shared_clock_cost.rs"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"at": "2026-10-03T15:49:41Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 11,
"change": {
"change": "evidence",
"kind": "review_outcome",
"source": "review-result:issue-51-continuity-design",
"review": "review-result:issue-51-continuity-design",
"outcome": "fixed"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:19:07Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 13,
"change": {
"change": "evidence",
"kind": "metric_observation",
"source": "Release shared-clock public-facade probe; exact55/601/1203events; baselineexit101 medians92.517484/7038.153041/12449.723852ms; treatmentexit0 medians10.511861/11.983571/17.701283ms; growth1.140/1.684x; unchanged capture/decode/model counters unchanged",
"reference": "crates/entity-eventlog/tests/shared_clock_cost.rs"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"at": "2026-10-03T16:20:46Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 13,
"change": {
"change": "evidence",
"kind": "review_outcome",
"source": "review-result:issue-51-runtime-adversary",
"review": "review-result:issue-51-runtime-adversary",
"outcome": "fixed"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"at": "2026-10-03T16:20:46Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 13,
"change": {
"change": "evidence",
"kind": "review_outcome",
"source": "review-result:issue-51-runtime-recheck",
"review": "review-result:issue-51-runtime-recheck",
"outcome": "no-op"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"at": "2026-10-03T16:29:30Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 16,
"change": {
"change": "evidence",
"kind": "review_outcome",
"source": "review-result:issue-51-provider-checker",
"review": "review-result:issue-51-provider-checker",
"outcome": "no-op"
}
}

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:35:43Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 16,
"change": {
"change": "evidence",
"kind": "ess_conformance_coverage_v1",
"source": "{\"completed_at\":\"1791045343826\",\"conformance_status\":\"passed\",\"counts\":{\"error\":0,\"failed\":0,\"passed\":17,\"skipped\":0,\"total\":17,\"unsupported\":0},\"coverage\":{\"counts\":{\"authored\":7,\"generated\":10,\"outside\":0,\"refused\":0},\"knowledge\":\"complete_inventory\",\"refused\":[],\"selection\":{\"filter\":{\"kind\":\"all\"},\"origins\":\"generated_and_authored\",\"scope\":{\"kind\":\"system\"}}},\"execution_status\":\"passed\",\"format\":\"ess-conformance-report/2\",\"implementation\":\"entity-runtime source-sha256:50edd1c86b576122b432d4d9d820d818712531ce4fa167d020bbf44ba83ee7e2;executable-sha256:a5e300d731bf76d39d7b322ad766f7142cc3afd5ce1a64701c88829841067ceb\",\"input_transport\":\"wrapped_raw_suite\",\"policy\":\"complete-selection/1\",\"producer_profile\":\"rust-scenario-status/1\",\"report_input\":\"target/provider-ess-conformance/report.json\",\"selected_ids\":[\"entity-provider.tracking.Batch/outcome/returned\",\"entity-provider.tracking.Create/outcome/returned\",\"entity-provider.tracking.Histories/outcome/returned\",\"entity-provider.tracking.Load/outcome/returned\",\"entity-provider.tracking.LookupBatch/outcome/returned\",\"entity-provider.tracking.Provision/outcome/returned\",\"entity-provider.tracking.Register/outcome/returned\",\"entity-provider.tracking.Reopen/outcome/returned\",\"entity-provider.tracking.Snapshot/outcome/returned\",\"entity-provider.tracking.SqlMutate/outcome/returned\",\"entity-provider.tracking/authored/multi-subject-histories-one-scope\",\"entity-provider.tracking/authored/unchanged-capture-retains-verified-state\",\"entity-provider.tracking/authored/unchanged-head-blob-tamper\",\"entity-provider.tracking/authored/unchanged-head-delete-blob-tamper\",\"entity-provider.tracking/authored/unchanged-head-event-tamper\",\"entity-provider.tracking/authored/unchanged-head-identity-tamper\",\"entity-provider.tracking/authored/unchanged-head-projection-tamper\"],\"selection\":{\"filter\":{\"kind\":\"all\"},\"origins\":\"generated_and_authored\",\"scope\":{\"kind\":\"system\"}},\"spec_digest\":\"ef6eb41f4dac9a7d51a5c0dc675933062d24096f195456a1dafe88ff8de672ac\",\"specification\":\"entity-provider/v1\",\"suite\":{\"digest\":\"sha256:7ed494f22f60f90f908dcc1050a915c2c8de1551a582f028b05e12aa879ebc99\",\"digest_profile\":\"sha256-json-bytes/1\",\"version\":\"ess-conformance/29\"},\"suite_input\":\"ess/provider-tracking/generated/suite.json\"}",
"reference": "target/provider-ess-conformance/report.json"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:38:23Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 16,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "Final task check exit 0; every ordered step completed; real PostgreSQL lane executed; all-feature runtime 186 passed; performance probe separately executed and passed",
"reference": "docs/ess/evidence/provider-tracking/README.md"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:38:23Z",
"actor": "human:timo",
"artifact": "story:bounded-batch-and-facade-reads",
"kind": "story",
"revision": 16,
"change": {
"change": "evidence",
"kind": "metric_observation",
"source": "Published-pin release probe exit 0, one test; medians 11.532148/13.049370/13.568977 ms at 55/601/1203 events, ratios 1.132/1.177 under unchanged 2x assertion",
"reference": "docs/ess/evidence/provider-tracking/performance-final.txt"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:02:54Z",
"actor": "human:timo",
"artifact": "story:declared-refusal-before-fulfillment-validation",
"kind": "story",
"revision": 6,
"change": {
"change": "evidence",
"kind": "verification",
"source": "cargo test -p entity-executor --locked: exact stored-field refusal failed before change and passed after; independent batch/retry controls pass",
"reference": "review-result:issue-49-adversary-public"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:02:54Z",
"actor": "human:timo",
"artifact": "story:declared-refusal-before-fulfillment-validation",
"kind": "story",
"revision": 6,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "cargo test -p entity-executor --locked: 22 passed, 0 failed; fmt and clippy exited 0",
"reference": "c6164443df9f303f4898f1de1abfc1c899e8c921"
}
}

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:28:40Z",
"actor": "human:timo",
"artifact": "story:declared-refusal-before-fulfillment-validation",
"kind": "story",
"revision": 12,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "CARGO_PROFILE_DEV_DEBUG=0 CARGO_BUILD_JOBS=2 task check exited 0 on integrated #49 and #50; PostgreSQL lane explicitly skipped because ENTITY_POSTGRES_URL unset",
"reference": "target/issue-wave-scratch/task-check.log"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:39:23Z",
"actor": "human:timo",
"artifact": "story:declared-refusal-before-fulfillment-validation",
"kind": "story",
"revision": 13,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "Final all-issue integration task check exit 0 with 421 original ESS scenarios passing and real PostgreSQL execution",
"reference": "docs/ess/evidence/provider-tracking/README.md"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"at": "2026-10-03T15:21:43Z",
"actor": "human:timo",
"artifact": "story:executor-input-refusal-before-existence",
"kind": "story",
"revision": 7,
"change": {
"change": "evidence",
"kind": "review_outcome",
"source": "review-result:issue-50-adversary",
"review": "review-result:issue-50-adversary",
"outcome": "no-op"
}
}

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:23:45Z",
"actor": "human:timo",
"artifact": "story:executor-input-refusal-before-existence",
"kind": "story",
"revision": 12,
"change": {
"change": "evidence",
"kind": "verification",
"source": "Original two RevisionConflict reproductions red before fix; 38 package tests green after implementation and independent review",
"reference": "review-result:issue-50-adversary"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T15:28:40Z",
"actor": "human:timo",
"artifact": "story:executor-input-refusal-before-existence",
"kind": "story",
"revision": 12,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "CARGO_PROFILE_DEV_DEBUG=0 CARGO_BUILD_JOBS=2 task check exited 0 on integrated #49 and #50; PostgreSQL lane explicitly skipped because ENTITY_POSTGRES_URL unset",
"reference": "target/issue-wave-scratch/task-check.log"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T16:39:23Z",
"actor": "human:timo",
"artifact": "story:executor-input-refusal-before-existence",
"kind": "story",
"revision": 13,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "Final all-issue integration task check exit 0 with 421 original ESS scenarios passing and real PostgreSQL execution",
"reference": "docs/ess/evidence/provider-tracking/README.md"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-03T18:39:22Z",
"actor": "human:timo",
"artifact": "task:release-0-26-0",
"kind": "task",
"revision": 3,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "task check on the 0.26.0 candidate with a real PostgreSQL 17.6 fixture; exit 0",
"reference": "target/release-evidence/task-check.log"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
format: aep.planning-md/3
id: decision-blocker:sqlite-cache-integrity-boundary
kind: decision-blocker
status: cleared
title: Choose the integrity boundary for SQLite warm cache verification
relations:
- blocks: story:bounded-batch-and-facade-reads
revision: 3
transitions:
- {from: "open", to: "cleared", at: "2026-10-03T15:26:44Z", actor: "human:timo", revision: 3}
---
## Question

The operator was asked whether a full verification on open followed by SQLite change tracking may establish unchanged state, detecting writes from any SQLite connection including SQL tampering, or whether every read must detect arbitrary raw database-file edits bypassing SQLite. No answer has arrived yet.

## Consequence

The narrowed SQLite boundary admits investigation of a provider-owned checkpoint and atomic append delta. The arbitrary-file boundary does not admit returning a cached answer merely because SQLite reports no change. Keep current complete verification until the operator answers; do not infer agreement from silence.

## Clear condition

Record the operator's chosen integrity boundary and reflect it in the provider contract and executable verification cases. This clears a decision only, not dependency-blocker:verified-provider-change-authority or any performance evidence requirement.

## Operator decision

The operator explicitly answered "Accept SQLite change tracking" on 2026-10-03. Full verification on open remains required. Warm reads may rely on SQLite-mediated change tracking and need not detect raw database-file modifications that bypass SQLite. Writes from other connections, including SQL tampering, must invalidate the cache. This resolves the integrity-boundary choice; provider change authority and implementation/performance evidence remain outstanding.
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
format: aep.planning-md/3
id: dependency-blocker:verified-provider-change-authority
kind: dependency-blocker
status: cleared
title: Issue 51 needs an integrity-preserving bounded-read provider contract
relations:
- blocks: story:bounded-batch-and-facade-reads
withholds: test_result
revision: 3
transitions:
- {from: "open", to: "cleared", at: "2026-10-03T16:38:23Z", actor: "human:timo", revision: 3}
---
## Evidence

The read-only scoping of issue #51 found no verified changed-content token or checkpoint authority in pinned Eventlog rev 0a0484634e8c640be29d6b6541d6cc1c1aaef7d3. See crates/eventlog-core/src/capture.rs:273-336 and src/lib.rs:1005-1017,1149-1179 in that revision; ER's adapter/scoped.rs:291-299 and adapter.rs:4159 require batch co-member closure for existing verification.

## Clear condition

An accepted, implemented and tested provider contract or an equally strong ER verification design demonstrates bounded shared-clock reads while detecting altered blobs and preserving complete batch assurance. The 55/601/1203 timing probe must meet the issue's 2x bound. A read-scope routing change alone does not supply this evidence.

## Next owner and action

Coordinator proposes the provider contract and cross-repository scope to the operator. Do not claim issue #51 fixed or weaken existing integrity assertions. Local facade work may proceed as an explicitly partial contribution after wave approval.

## Resolution

The operator accepted the SQLite-visible integrity boundary. Eventlog6983cc25eb92e07844b3a6fa3e0decbdb300f43c implements the optional proof contract and is bot-published with signed common checks, independent regression review and a final545-case PostgreSQL/TLS proof. Runtime1516e748 plus integration receipt/test/docs work preserves full-open verification, complete-new-batch assurance, and external SQL tamper refusal. The exact published-pin integration gate exits0 with421+17 ESS scenarios, all supported and none skipped. Final release probe medians11.532148/13.049370/13.568977ms at55/601/1203 events give1.132/1.177x growth and pass the unchanged2x assertion. Evidence is retained in docs/ess/evidence/provider-tracking and the immutable review records. Clear condition met without changing default constructor behavior or claiming consumer adoption.
Loading
Loading