You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md
+22-11Lines changed: 22 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1231,18 +1231,29 @@ is gated by evidence below, not by calendar dates or this PR's merge status.
1231
1231
| New-Goal default decision (F) | Maintainers accept the qualified profile and canary results, operational diagnostics, backup/restore procedure, release instructions and default-disable path. Ship the default change in a separate disclosed release change. | Apply only to newly created eligible local Goals. Existing explicit file selections remain pinned. Unsupported runtimes/filesystems require an explicit supported choice; no silent backend switch on open failure. |
1232
1232
| Existing-Goal migration and file retirement | Migrate opt-in cohorts using the reviewed fenced workflow; reconcile receipts, history, projections and rollback after each cohort. Inventory the last file-primary callers and compatibility windows before removing any path. | Each Goal needs explicit migration authority. Retire file as the ordinary primary only after that evidence; retain reference/import/export support until its own callers and retention duties end. |
1233
1233
1234
-
**Current evidence position (rechecked 2026-09-13).**#4121 merged as
1234
+
**Current evidence position (rechecked 2026-09-15).**#4121 merged as
1235
1235
`bde1632bb6f29aeb9a8b4ac23ead3e98ba2f2f55`, delivering the first candidate
1236
-
milestone. It remains subject to profile qualification and promotion; it is
1237
-
not completion of lane L. Its head pointer is bounded and
1238
-
operation/cursor lookups are indexed, but it retains full historical projections
1239
-
and counts a covering index for continuity. That count grows with history;
1240
-
current/accessed-row digests are checked, not every historical payload per read.
1241
-
The qualification entrypoint now separates a small rehearsal from an explicit
1242
-
64-KiB 10k/100k storage axis, with p99/counts, cold CLI, RSS and a
SQLite is an **opt-in local conformance candidate**, behind the existing
4
4
TypeScript `AuthorityStore` interface. File remains the default. This slice
5
-
does not promote a goal, migrate existing authority, enable cross-host writes,
6
-
or qualify ten elapsed days of operation.
5
+
does not promote a goal, run a live cutover, enable cross-host writes, or
6
+
qualify ten elapsed days of operation. It does provide the explicit
7
+
version-1 to version-2 database migration described below.
7
8
8
9
## Placement and persistence
9
10
@@ -18,24 +19,37 @@ directory. Metadata binds the goal, schema version and random database
18
19
incarnation. Provider revisions combine that incarnation with a monotonic
19
20
integer sequence; they are not authority revisions or lease epochs.
20
21
21
-
The version-1 schema contains:
22
+
The version-2 schema contains:
22
23
23
24
| Table | Contract |
24
25
| --- | --- |
25
26
|`metadata`| Version and database/goal identity |
26
-
|`head`| One bounded pointer to the current committed projection |
27
-
|`commits`| Unique operation ID, canonical commit digest, ordered cursor, original receipts, events and full projection |
27
+
|`head`| The live committed projection, its state digest and one cursor |
28
+
|`commits`| Unique operation ID, canonical commit digest, ordered cursor, original receipts and events, one exact state delta, its state digest and parent state digest |
29
+
|`checkpoints`| One full projection and its digest per bounded window |
28
30
29
31
`commits` also serves as the durable projection outbox used by
30
32
`scanCommitted`. There is no independent ACK or second receipt authority.
31
33
Existing consumers resume by cursor. A unique operation index makes receipt
32
-
lookup and cursor paging indexed. The common continuity check counts the compact
33
-
covering index, so total read/write cost is not independent of history length.
34
-
It does not deserialize the complete retained payload history. Historical receipts and full projections are retained without
35
-
pruning. Fixed live state therefore produces linear database growth, not
36
-
bounded total disk use. Growing application projections require separate
34
+
lookup and cursor paging indexed.
35
+
36
+
Retention is bounded by window instead of by history: every commit keeps one
37
+
exact delta, and one full projection is retained per checkpoint window
38
+
(`authority_state_log.ts`, 64 commits per window). A live read resolves the head
39
+
from the head row, its retained transaction and the cursor bounds; a historical
40
+
read rebuilds at most one window from the covering checkpoint. Retained deltas
41
+
are therefore the only part that still grows with history, and their size is
42
+
proportional to what each commit changed. Original receipts and events are
43
+
retained without pruning, so fixed live state with large receipts still grows
44
+
with history. Growing application projections require separate
37
45
retention/compaction work.
38
46
47
+
The rehearsal profile measures this profile directly: at 1,000 commits with a
delta bytes, against 65,536,000 bytes for one full copy per retained commit.
50
+
Formal 10k/100k evidence still requires the separately authorized matched
51
+
profile.
52
+
39
53
Writes use `BEGIN IMMEDIATE`, a five-second busy timeout, WAL and
40
54
`synchronous=FULL`. The head, receipt, events and outbox row commit together.
41
55
Before-COMMIT failures roll back; a COMMIT error reports an ambiguous outcome
@@ -49,18 +63,29 @@ rotation, corruption repair, or network-filesystem sharing is supported.
49
63
50
64
## Read integrity
51
65
52
-
Authority reads share one SQLite snapshot for metadata, head and requested rows.
53
-
The same check runs inside the write transaction before any new commit row:
54
-
positive unique integer cursors must have `min=1` and `count=max=head`. Thus a
55
-
missing head, rolled-back head, or internal cursor gap is rejected as
66
+
Authority reads share one SQLite snapshot, and writes run the same live proof
67
+
inside their transaction before publishing a new commit row. The proof is
68
+
layered so that each layer pays only for what it returns:
69
+
70
+
| Layer | Proves | Cost |
71
+
| --- | --- | --- |
72
+
| Live head (`loadAuthority`, `commitAuthority`) | Head row digest over the live projection, the retained transaction at that cursor reproducing its exact commit digest, parent linkage, `min=1`/`count=max=head` cursor continuity, and the presence of the checkpoint that covers the head | One head row, one retained row, one parent digest and index lookups; independent of retained history |
73
+
| Materialized history (`scanCommitted`, `readReceipt`) | Every row from the covering checkpoint through the requested span, including each delta, state digest and parent lineage; paged scans also prove the lookahead row used for `has_more`| At most one checkpoint window plus the requested span |
74
+
| Archive audit (`verifyAuthorityHistory`) | The complete delta chain from the empty root, every checkpoint against retained history, and the final state against the head | Linear in retained history; qualification and recovery only |
75
+
76
+
A missing head, rolled-back head, internal cursor gap, rewritten receipt/event,
77
+
orphaned parent digest or mismatched state digest is rejected as
56
78
`provider_protocol_violation` before returning authority or accepting a write.
79
+
Preparing a commit also re-applies its own delta and requires byte equality with
80
+
the committed projection before anything is written.
57
81
58
-
The newest row's canonical commit digest is recomputed on every authority read
59
-
and write. Historical receipt reads additionally validate their selected row;
60
-
paged scans validate each returned row and the lookahead row used for
61
-
`has_more`. The digest includes the operation ID, projection, events, receipts
62
-
and expected predecessor revision, reconstructed from the unchanged v0 sequence
63
-
contract. No schema migration or alternate digest format is introduced.
82
+
Two shapes are deliberately outside the live proof because the live head never
83
+
reads them: the delta of the newest retained row, and the projection of the
84
+
checkpoint the live head resumes from. Both are refused by every read that
85
+
materializes their span and by the archive audit, and neither can change the
86
+
authority value a live read returns. The commit digest is unchanged from v0
87
+
(operation ID, projection, events, receipts, expected predecessor revision), so
88
+
cursors, provider revisions and stored digests stay comparable.
64
89
65
90
This is integrity validation of the current and accessed evidence, not a full
66
91
cryptographic audit of every historical payload on each call. Unaccessed older
0 commit comments