You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Files Changed: add bounded receipt, assessment, and evidence storage #1076
Files Changed: add bounded receipt, assessment, and evidence storage
Important
Problem - Session diffs and external preimages are split across ephemeral metadata, snapshots, and host-local artifacts. There is no bounded durable representation for operation groups, immutable receipt facts, current assessments, or root-owned evidence. Approach - Add compact root-owned operation, receipt, and assessment storage to the session database, with a separate bounded host-local evidence store. Adapt existing external-diff state through this storage boundary without widening legacy output. Scope - in: storage schema, migration, quotas, pagination, retention, compaction, evidence references, and existing external-diff compatibility. out: mutation-route adoption and UI replacement. Assumptions - The typed lineage root from the preceding slice is available.
Acceptance Criteria
One operation group can atomically publish immutable receipts for all declared resources.
Immutable receipt facts are separate from append-only or derived assessments.
Assessments represent observation confidence, net state, evidence availability, revision, and expiry without rewriting receipt history.
Receipt metadata, row count, and evidence bytes are bounded per root with paged retrieval and documented retention.
A known local mutation that would exceed the active root budget is refused before filesystem work begins.
Evidence resides outside the session database and can hold bounded patches, preimages, or structured metadata without entering legacy session output.
Existing external-diff data can be read through a compatibility adapter without granting old sessions full-provenance status.
Root deletion removes receipt data and evidence according to retention policy; orphan cleanup is idempotent.
Existing external baseline and assessed-diff persistence
Deliberation Resolution
An operation group advances through prepared, evidence_ready, and committed. Evidence is written atomically before the database transaction references it; an orphaned evidence artifact is swept, while a committed receipt with missing evidence receives an unavailable assessment and never renders a patch.
The injected root budget exposes four deterministic units: max_receipts, max_metadata_bytes, max_evidence_bytes, and retention_ms. Preparation reserves declared receipt and metadata capacity; evidence above its byte limit becomes metadata-only without losing the receipt.
Pagination is by immutable receipt creation sequence within a root. Retention begins when the root is deleted or reaches its configured terminal age; compaction may remove expired evidence and assessments but preserves a compact receipt tombstone until root retention ends.
A v1 external baseline maps to a legacy_external compatibility record with no operation group, no lineage ownership, and no full-provenance display claim.
Files Changed: add bounded receipt, assessment, and evidence storage
Important
Problem - Session diffs and external preimages are split across ephemeral metadata, snapshots, and host-local artifacts. There is no bounded durable representation for operation groups, immutable receipt facts, current assessments, or root-owned evidence.
Approach - Add compact root-owned operation, receipt, and assessment storage to the session database, with a separate bounded host-local evidence store. Adapt existing external-diff state through this storage boundary without widening legacy output.
Scope - in: storage schema, migration, quotas, pagination, retention, compaction, evidence references, and existing external-diff compatibility. out: mutation-route adoption and UI replacement.
Assumptions - The typed lineage root from the preceding slice is available.
Acceptance Criteria
Testing Decisions
Key Decisions
Constraints & Invariants
Prior Art
Deliberation Resolution
prepared,evidence_ready, andcommitted. Evidence is written atomically before the database transaction references it; an orphaned evidence artifact is swept, while a committed receipt with missing evidence receives anunavailableassessment and never renders a patch.max_receipts,max_metadata_bytes,max_evidence_bytes, andretention_ms. Preparation reserves declared receipt and metadata capacity; evidence above its byte limit becomes metadata-only without losing the receipt.legacy_externalcompatibility record with no operation group, no lineage ownership, and no full-provenance display claim.Source
Part of #972. Blocked by #1075.