{397.1} Invariant triage — the nightly lane under the corpus-reframe model
{397.1} Invariant triage table — survive / retire / reshape
Section titled “{397.1} Invariant triage table — survive / retire / reshape”Status: RATIFIED — {397.3} owner board, S513 (all rulings incl. the D-397-A
Option C amendment after the owner-directed cocoindex skill check; board preserved at
reports/s513-id397-lane-target-board.html). Non-mutating delta document (the id-62
P4-RECONCILIATION precedent): no register spec is edited here; ratified verdicts are
executed by the S2-execute and S8 mints. Grounding: RESEARCH.md (this dir) — four-lane
research pass, S513; repo @ b0b72a0c; census #41 (tasks/id-128.md journal).
§0 Universe declaration and conventions
Section titled “§0 Universe declaration and conventions”The triage universe is the cocoindex-nightly assertion surface (OQ-397-1 assumption; siblings disposed in §7):
| Register | Range | Defining home | Age caveat |
|---|---|---|---|
| id-28 flow-scaffolding | Inv-1..27 | id-28/PRODUCT.md:56-132 | pre-127; S265 amendment layer |
| id-53 stage-5 | Inv-1..21 | id-53/PRODUCT.md:47-105 | pre-127; one S299 correction |
| id-36 extraction contract | Inv-1..26 | id-36/PRODUCT.md:24-90 | pre-127; S287 Inv-2 reconciliation |
| id-62 fixture staging | Inv-1..29 | id-62/PRODUCT.md:157-544 + TECH.md:443-471 | P4 re-authored (B1), but pre-reframe-execution |
| id-52 form extraction (nightly subset) | Inv-5/6/7/16/17/18/25 | id-52/ACCEPTANCE.md:66-90 | pre-127; DR-014 path |
| id-56 content model (C-subset) | C-10..13, 21, 22, 30, 31, 54 | id-56/PRODUCT.md:49-119 | pre-127; S276 amend layer |
Conventions, all binding on every verdict below:
- Anchor format:
<file>:<line> → <owning-spec>/<artefact>:<line>. BareInv-Ntokens are ambiguous in this repo by construction (RESEARCH Issues §4: Inv-7 has three live owners, Inv-11 four, Inv-27 two inside the nightly directory). Cross-spec references always carry theid-NNprefix. - Register-age posture (owner steer, S513): every register pre-dates id-127.
SURVIVE verdicts required a corpus-reframe consistency check
(
corpus-reframe-review.html+bundle-doctrine.md+id-396/TECH.md), not default inheritance. - Substrate-verify dimension: behaviour-survives ≠ binding-survives. Rows whose
text binds
content_items-era substrate (retired by id-131/id-317; poll seams only half-retargeted at M6) carry [SV] — the S2-execute implementer verifies the live binding before porting the assertion. - Verdict vocabulary (P4 precedent, extended):
SURVIVES·SURVIVES [SV]·REFRAME(behaviour holds, mechanism/substrate restated) ·RESHAPE(contract changes under the target model) ·MOOT(surface no longer exists) ·DELETE(removed, not replaced) ·FUTURE(contract deferred to v1.1 substrate) ·FORK-PENDING(blocked on the §3.1 owner decision).
§1 Verdict summary — the count is the argument
Section titled “§1 Verdict summary — the count is the argument”Of the 97 ruled items (27+21+26+29+7 subset+9 C-ids, minus id-53 Inv-19
out-of-lane), post-ratification: ~75 SURVIVE (12 of those [SV]; five with the
§3.1 mechanism note), 1 RESHAPE (id-53 Inv-9 — the curation-pinning co-mint),
7 REFRAME, 4 FUTURE, 1 demotion, 0 outright DELETE, plus 8 new-mint
surfaces (§5) with no invariant today.
That distribution is the verdict: the registers do not need wholesale re-spec. The load-bearing change concentrates in three places — (i) ONE owner fork over the op_id/memo doctrine (§3.1, six invariants, three census failures); (ii) the run-observation contract, which today is entirely uncontracted (the 10 s walk pump exists only in workflow YAML; no invariant governs walk triggering, quiescence, or run selection — §3.2 + §5); (iii) substrate rebinding residue from the record-model pivot (§3.5). The harness shape is where the wholesale work lives — that is {397.2}, not the registers.
§2 What SURVIVES
Section titled “§2 What SURVIVES”| Surviving surface | Invariants | Why it survives |
|---|---|---|
| id-62 staging harness, whole contract minus Inv-20 | id-62 Inv-1..19, 21..29 | Topology-agnostic byte-drop + driver + activation + posture; re-authored for B1 post-P4; upsert-absorb strengthens Inv-11 (idempotent re-stage is now designed behaviour, id-396/TECH.md:88-96). Trigger policy Inv-28/29 survives as policy. |
| Six-stage topology + failure discipline | id-28 Inv-3 (+S265 Stage-5 rider id-28/PRODUCT.md:62), Inv-22..27 | Stage semantics, layered retry (OQ-E), DLQ composite, structured logs, no-partial-writes are walk-shape-independent. Census #18/#19 failures are observation races, not topology breaches (§4). |
| Run forensics spine | id-28 Inv-8, Inv-12, Inv-16..19 | Image identity, op_id→run PK resolution, one-row-per-invocation, per-stage rollup, recordPipelineRun() discipline, no pipeline_failures table. Inv-16 is target-compatible (N walks → N rows; accumulation is designed, id-396/TECH.md:106) — its failing test is dead, not the invariant (§4 #10). |
| Extractor contract, whole register | id-36 Inv-1..21 + DO-NOT-BUILD guards 22..24 (+ carried OPENs 25/26) | Typed discriminated-union outputs, routing, validation-failure discipline are per-item semantics untouched by the walk model. Inner LLM memos confirmed intact by bl-239 (“LLM seams are NOT busted”). Inv-15/16 [SV] (bind content_items.id lineage — §3.5). Inv-2 already reconciled S287. |
| Stage-5 structural contract | id-53 Inv-1, 2, 4, 6, 8, 12, 13, 15..18 | Post-fan-out placement, UPDATE-never-INSERT, failure semantics, span/confidence/context mappings, faiss pin — walk-shape-independent. Provability of Inv-1/13 degrades without cross-doc resolution (tier note §3.4). |
| Pipeline ingestion SLAs | id-28 Inv-2 [SV], Inv-5, Inv-7 | Per-file observability within SLA; nested dirs; sidecar-owned extraction. Poll deadlines re-parameterise under {397.2} (corpus-growth, §3.3) — the invariant is not the budget number. |
| Form-extraction nightly subset | id-52 Inv-5, 6, 7, 16, 17, 18, 25 | DR-014 manual-upload path, orthogonal to walk shape; env-gated tests are correct-as-authored (id-52/ACCEPTANCE.md:69-89). |
| Chunking + embedding mechanics | id-56 C-10, 11, 12, 13 [SV], C-30 | Budget-driven splitting, chunk table shape, embedder identity are per-item semantics. C-13’s two owed migrations + heading-column disposition ride their own task ({56.3}), noted not re-owned. Census #3 failure is a helper defect, not C-11/C-12 (§4). |
§3 What CHANGES
Section titled “§3 What CHANGES”§3.1 The op_id/memo doctrine — D-397-A, RULED Option C
Section titled “§3.1 The op_id/memo doctrine — D-397-A, RULED Option C”Three layers in conflict (RESEARCH Issues §2):
- Normative, owner-ratified (S265, OQ-A): “a no-op re-ingest does NOT re-stamp
op_id;full_reprocessDOES” —id-28/PRODUCT.md:84, restated by id-53 Inv-7 (id-53/PRODUCT.md:63) and id-56 C-21/C-31 (id-56/PRODUCT.md:81,91; acceptanceid-56/TECH.md:204). - Empirical ({75.17}/bl-239): the outer memo is busted every walk —
flow_op_idis a memo input; every walk re-runs every item and_upsert_source_documentre-stamps every row (flow.py:1793-1802, 3812-3815;test_file_branch_memo_fingerprint.py:9-32). - Target model (id-396 D1): upsert-absorb accepts per-walk re-declares and makes
them idempotent (the id-398 PK re-seed) — leaning to the installed reality without
ruling what
op_idthen means.
RULED: Option C — synthesis (S513 board; Option B initially ticked, amended after
the owner-directed cocoindex skill check). The engine’s memo contract settles the
fork: memo fingerprints cover function inputs + code only, and ContextKey
values default to detect_change=False — “resources not affecting computation” —
invisible to the fingerprint (cocoindex skill, references/api_reference.md:176-179).
The defect is therefore the channel: flow_op_id as a kwarg. Passed via context,
unchanged items memo-skip every walk, rows keep their last-materially-changed op_id,
and per-walk cost drops from O(corpus) to scan+skip. The ruling:
- The upsert-absorb write path stands (id-396 D1 + id-398 PK re-seed) — the
safety net for re-declares that legitimately happen: changed bytes,
versionbumps,full_reprocess, post-sweep re-stage. - The S265 semantic is NOT superseded — it is restored by the idiomatic
mechanism: op_id supplied via a
ContextKey(detect_change=False), removed from the memoised component’s kwargs, at S2-execute. - id-28 Inv-11, Inv-15 · id-53 Inv-7 · id-56 C-21, C-31 → SURVIVE with one shared mechanism note (the context-passing fix); census #10/#13 (and #4’s op_id half) become honest defect detectors against the restored semantic.
- id-53 Inv-9 → RESHAPE (the one surviving casualty): its op_id-scoping
protection still collapses on
full_reprocesspaths, which legitimately re-stamp everything and put admin-merged rows back in Stage-5 scope (id-53/PRODUCT.md:59,69) — census #41 failure #1 (admin merge reverted) is the live symptom. Co-mint: curation-pinned rows the walk may never UPDATE — the R3 promotion-boundary rule applied at the entity layer (corpus-reframe-review.html§“the pipeline must never overwrite a promoted record”). - C-31’s embedding half stays held on VQ-1 (§8): census #4 shows ~1e-5-different vectors on unchanged bytes — measure the embed seam before ruling that half.
§3.2 The run-observation contract — REFRAME + new mints
Section titled “§3.2 The run-observation contract — REFRAME + new mints”Today NOTHING contracts how a test observes “the run I caused”: the 10 s walk pump is
workflow YAML (cocoindex-nightly.yml:709-729), op_id is flow-scope one-per-walk
(flow.py:3871), and helpers read pipeline_runs status-blind
(test-helpers.ts:~305,330-353). Verdicts:
- id-28 Inv-1 → REFRAME: “one run scoped to that change” becomes “one run per walk; a change is attributable to the walk that absorbed it” — per-file run scoping is unimplementable under whole-corpus walks (census #8). Final wording depends on the {397.2} walk-trigger ruling (OQ-397-3).
- id-53 Inv-13, id-56 C-54 → SURVIVES + run-selection rider: “stable after
status='completed'” needs a which-run idiom once runs accumulate and a pump (or any live watch) keeps minting newer ones. - Helper defects (not invariants): status-blind
maybeSingle()reads; poll-then-join op_id races. These are S2-execute items listed under §5 NM-5.
§3.3 Poll budgets under corpus growth — {397.2} input, no verdict change
Section titled “§3.3 Poll budgets under corpus growth — {397.2} input, no verdict change”Six census timeouts (#5, 6, 11, 12, 14, 16, 17 — see §4) are budget starvation:
catch-up walks scan all sources per call (cocoindex SKILL.md:195-197), corpus grows
monotonically through the run, back-half files fail at exactly their ceilings. The
invariants survive; the harness shape must bound per-test corpus cost (sweep, staged
cohorts, or walk-trigger change) — {397.2}.
§3.4 Entity-identity provability — tier quarantine (OQ-397-2)
Section titled “§3.4 Entity-identity provability — tier quarantine (OQ-397-2)”id-53’s identity-dependent cluster — Inv-3, 11, 21 (strong), Inv-10, 14, 20 (direct),
Inv-1, 5, 7, 13 (discriminating power only) — is untestable under the scheduled mock
tier: canned entities collapse cross-document identity (census #1, #9; RESEARCH Issues
§3e). Invariants SURVIVE; their proof tier changes: quarantine at mock (skip
with a named reason) + prove on real-tier dispatch, or make the mock
per-fixture-deterministic. Interacts with id-395/D2 (tier joins the pair-resolver
cache key). The triage table refuses to let a mock artefact adjudicate an invariant
either way.
§3.5 Substrate rebinding — the record-model residue [SV] rows
Section titled “§3.5 Substrate rebinding — the record-model residue [SV] rows”id-131 killed content_items; poll seams were only half-retargeted at M6 (census
class-1; {377.6} inbox). Rows whose TEXT binds that era: id-28 Inv-2, Inv-4
(mechanism prose), Inv-11 (column list) · id-36 Inv-15, Inv-16 (“references
content_items.id, never source_documents.id” — the record-model successor of that
lineage rule must be named, not assumed) · id-56 C-13, C-21. Verdict: SURVIVES
[SV] — behaviour intent holds; S2-execute verifies each live binding
(table/column/poll seam) against the record model before porting the assertion, and
the ported test cites the successor substrate explicitly.
§3.6 Topology-stale prose — mechanical REFRAME
Section titled “§3.6 Topology-stale prose — mechanical REFRAME”id-28 Inv-6 (Cloud Run Service, Service URL) and Inv-10 (scale-to-zero cold start) →
REFRAME to B1 exactly as id-62’s P4 already did for its own register
(P4-RECONCILIATION.md:96-130 precedent): behaviour halves survive (health probe;
first-extraction-after-restart budget), container-platform prose is restated.
§3.7 FUTURE class — deferred-substrate invariants
Section titled “§3.7 FUTURE class — deferred-substrate invariants”id-28 Inv-13, Inv-14 (audit_log op_id forensics; id-28/PRODUCT.md:92 defers the
audit_log table to v1.1) and id-56 C-22 (RAISE-LOG audit, table deferred) →
FUTURE: contracts stand, not testable against v1 substrate. Census #2’s failure
is a broken skip-guard, not the invariant — the correct table-absent guard exists
verbatim in memo-hit-pipeline-run…:218-237; the FUTURE test must guard, not fail.
§3.8 Demotion
Section titled “§3.8 Demotion”id-62 Inv-20 (dropFixture cleanup ownership) → SURVIVES, demoted: under the D1
pre-run sweep it is “good hygiene, no longer load-bearing” (id-396/TECH.md:100-104).
The sweep inherits the scope guard: fixture-prefixed TEST rows only; showcase data
never sweep-eligible (owner amendment, id-396/TECH.md:107-111).
§4 Census #41 — the 19 failures adjudicated
Section titled “§4 Census #41 — the 19 failures adjudicated”Classes: RB real-breach candidate · HM harness mechanics (root causes a–e, RESEARCH Issues §3) · DT dead/stale test · FP fork-pending (§3.1) · RS retired-surface (census class-1). Anchors: RESEARCH “Census #41” table.
| # | Test | Verdict | Disposition |
|---|---|---|---|
| 1 | admin-merge-coexistence | RB (Inv-9 RESHAPE) | The §3.1 Inv-9 casualty, live. The ruled curation-pinning co-mint closes it; also tier-confounded (e). Do not hot-fix. |
| 2 | audit-log-shipping | DT / RS | FUTURE invariant + broken guard; one-line fix at S2-execute (§3.7). |
| 3 | chunking C-11/C-12 | HM (b, c) | Status-blind helper read in_progress zeros. C-11/12 SURVIVE. |
| 4 | chunking C-31 | HM + VQ-1 | Re-embed on unchanged bytes: op_id half becomes an honest detector once the §3.1 context fix lands; embed-seam determinism measured before the embedding half is ruled. |
| 5, 6, 12, 14, 16, 17 | six poll timeouts | HM (d) | Budget starvation (§3.3). Invariants survive. |
| 7 | cross-workspace-isolation | HM (a) | Two fixtures, one walk, one op_id — flow-scope op_id, not an isolation breach. Underlying id-53 Inv-21 also tier-quarantined (§3.4). |
| 8 | file-change-detection | HM (a) | Per-file run claim vs corpus-level key; rides the Inv-1 REFRAME (§3.2). |
| 9 | legacy-alias-preload | HM (e) | Tier quarantine (§3.4). |
| 10 | memo-hit-pipeline-run | DT | Asserts a JSONB path no producer writes — id-28 Inv-16 has NEVER been honestly proven. Rebuild the test at S2-execute regardless of fork branch. |
| 11 | op-id-round-trip | HM (d) | Timeout; id-53 Inv-6 survives. |
| 13 | op-id-stamping | HM (b) + RS | Class-1 title seam (M6 half-retarget) AND read-skew mechanism; its op_id-equality half becomes an honest detector under the ruled §3.1 semantic. The census’s deliberate double-listing stands. |
| 15 | sidecar-version-metadata | HM (b) + DT | op_id moving target now; stale EXTRACTOR_ID_KEYS (misses extractor_version) will fail it even when fixed. |
| 18 | stage-topology (counts) | HM (b) | Moving-target op_id; Inv-3/17 survive. |
| 19 | stage-topology (embeddings) | RB [SV] | 0 record_embeddings for owner_kind='source_document' while the sd row landed. The one failure with no harness explanation — verify the DR-036/owner_kind binding, then treat as a real write-path defect if it holds. |
Net honest read of the 19, post-ratification: 2 real breaches (#19 [SV]; #1 =
the Inv-9 RESHAPE the curation-pinning co-mint closes), 3 dead tests,
14 harness-mechanics (incl. #4/#13’s op_id halves, honest detectors once the
§3.1 context fix lands). Nothing here is “F4 back”; nothing gets hot-fixed ahead of
the S2-execute mint.
§5 New proof surface — invariants/tests that do not exist today
Section titled “§5 New proof surface — invariants/tests that do not exist today”| # | Mint | Source of obligation |
|---|---|---|
| NM-1 | ingest-once lineage: walked once, derived rows asserted to SURVIVE later walks + orphan cleanup | id-396/TECH.md:68-72; corpus-reframe-review.html §push-back ② |
| NM-2 | keep-and-watch lineage: re-walk on byte change re-derives | same |
| NM-3 | Legacy .xls/.doc mime-coverage over the two D3 adopted orphans | id-396/TECH.md:48-52 |
| NM-4 | Walk-trigger contract — the pump/trigger model becomes a contracted invariant instead of workflow YAML | §3.2; OQ-397-3 |
| NM-5 | Quiescence + run-selection primitives (test-visible “walk N complete, no newer walk started”; status-filtered run reads) | §3.2 |
| NM-6 | Pre-run sweep + its scope guard (fixture-prefixed only; showcase untouchable) asserted, not just performed | id-396/TECH.md:100-111 |
| NM-7 | Class-2 repro protocol: if ownership give-ups survive the rebased walk shape, they graduate to a real defect with a clean repro | id-397 goal; §6 |
| NM-8 | Census read gate per run: zero UniqueViolations, same-bytes population green, fixture population = manifest | id-396/TECH.md:171-173 |
Plus the standing coupling: the lane is the wiring-census’s live-population producer —
any lane-scope reduction ships with a census-impact note
(census-protocol.md:127-129).
§6 Class-2 disposition
Section titled “§6 Class-2 disposition”Census #40 was vacuous for class-2 (walks died at F4 first). #41 is the first run where walks completed — and its 19 failures contain no ownership give-up signature (no stage-while-walking churn; the contention class did not reproduce). Disposition: class-2 is provisionally dissolved by the F4 fix + absorb semantics, exactly as the charter hypothesised (“should dissolve with the legacy walk shape”) — but the clean test is the first post-{397.2} nightly under the rebased harness with NM-5 quiescence in place. If a give-up appears there, NM-7 graduates it to a defect with repro. Reader of record: this task, not id-128 (OQ-397-6 resolved by this section, pending board nod).
§7 Out-of-scope dispositions
Section titled “§7 Out-of-scope dispositions”- pytest-nightly / integration-nightly surfaces (id-81 cross-run, id-101-via-id-109 parity, id-63 counters, orphan display-name C-1): excluded from this table (OQ-397-1). id-81’s cross-run invariants are the closest cousins to NM-1/NM-2 — flagged as a consistency check for the S2-execute implementer, not ruled here.
- id-101: flow.py write-site cites only; no cocoindex-nightly assertion surface. Owner steer notes it as likely-superseded — its Inv-4/15/16/17 flow.py citations get resolved (not ruled) whenever those write sites are next touched. id-9: zero intersection (docs-site scope).
- Orphans (
Inv-30intaxonomy-consistency.test.ts:14,72; display-nameC-1×6 files; markdownC-1×1): home-or-retire rows routed to the S6 sweep with the rest of the citation-hygiene class (stale spec paths,id-101/TECH.md:261namespace leak,id-62/PRODUCT.md:132old-numbering cite). - id-53 Inv-19 (B:97+S299 rider): task-gating invariant (ID-60 observation window), not a lane assertion — out of table, noted for the initiative record.
§8 Rulings record — {397.3} board, S513 (all RATIFIED)
Section titled “§8 Rulings record — {397.3} board, S513 (all RATIFIED)”- D-397-A = Option C (§3.1) — absorb write path + S265 restored via context-passed op_id + Inv-9 curation-pinning co-mint. (Option B ticked first; amended to C after the owner-directed cocoindex skill check.)
- OQ-397-1 — universe boundary ratified as declared in §0.
- OQ-397-2 — tier quarantine: identity cluster skips at mock with named reasons the census counts separately; proven on real-tier dispatch; cadence set later.
- OQ-397-3 — W2 (explicit awaited walks; pump deleted) — HARNESS.md §2.
- OQ-397-4 — dead-test fixes (#2, #10, #15) land inside the S2-execute mint.
- OQ-397-5 — orphan invariants + citation-hygiene class route to the S6 sweep.
- Class-2 — provisionally-dissolved disposition ratified; clean test = first post-rebase nightly; id-397 is reader of record (resolves OQ-397-6).
- VQ-1 — embed-seam determinism measurement rides S2-execute; C-31 embedding half held until measured.
§9 Grounding
Section titled “§9 Grounding”Authored from: the four S513 research digests (RESEARCH.md, this dir); registers
extracted verbatim-compressed from id-28/id-53 (S513 lane) and id-36/id-52/id-56
(S513 lane); census #41 log (notes/census-41-vitest-run-30490593136.log, this dir);
id-396/TECH.md; census-protocol.md; corpus-reframe-review.html +
bundle-doctrine.md (owner-designated authority docs, S513);
id-62/P4-RECONCILIATION.md (format precedent). No register spec, task file (other
than id-397’s own journal), or code file was modified in producing this table.