lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

authored_draft_submission.v1.json (4602B)


      1 {
      2   "schema": "radroots.authored-draft-submission.v1",
      3   "status": "implemented",
      4   "owners": ["radroots_storage", "radroots_storage_sqlite", "radroots_sync"],
      5   "source": "Capture the existing immutable draft ID, revision, author, payload schema, optional scope, payload digest, editable stage and timestamps. Initial submission requires the current head to match that capture. The source remains editable and is never rewritten by submission.",
      6   "identity": "The stable submission lookup key hashes the fixed v1 domain, the 32-byte author account and the nonzero 16-byte caller command ID. Context/scope and semantic input are compared within that key; they never change its identity. Caller generation and request digest do not determine identity.",
      7   "intent": "The caller owns a distinct initial ReadyToSign or Queued draft containing the complete immutable semantic request, including app actor/account context, media and target policy. Storage requires matching source author and scope, operation association and captured time. Every prepared artifact must be an initial unsent plan by that author. Storage does not interpret an application payload schema or authorize signing.",
      8   "transaction": "One existing BEGIN IMMEDIATE transaction installs operation, artifacts, delivery plans, immutable intent, ordinary Prepare receipt and the composite submission receipt. The latter is the source-to-intent association. No second connection, generic SQL API, journal, signer or network callback is introduced. All intermediate failure and abandoned precommit work rolls back; success is returned only after commit.",
      9   "replay": "Lookup the composite receipt before source-head CAS. Compare its validated full captured source, full intent bytes and all preparation fields independently of the caller input digest. Exact replay returns the original operation even after later edits; differing input under the same author/command conflicts. Ordinary Prepare identity/digest/replay behavior stays unchanged so Sync resumes signing using its existing path.",
     10   "query": "Require exact independent author, payload schema and optional scope. Scan current heads by stable ascending draft ID with a version-1 context-bound continuation and at most 256 results. Each page uses and releases one read snapshot. A changed revision cannot move its ID; new IDs behind a cursor require a later sweep. This is not a frozen inventory across pages.",
     11   "corruption": "Return typed per-record corruption locators, retaining source evidence and continuing after each ID. Known foreign schemas/scopes are excluded before snapshot loading. Historical records with unknown schema metadata expose only an author-bound opaque ID/revision locator across that author's contexts, never payload. Protected-data/backend unavailability is an operation error, not row corruption.",
     12   "bounds": {"page_records": 256, "metadata_lookahead": 1, "decoded_page_payload_bytes": 4194304, "serialized_page_snapshot_bytes": 16777216, "existing_atomic_receipt_snapshot_bytes": 4194304},
     13   "migration": "Forward runtime schema 14 atomically adds generic schema/scope metadata and a query index. Safely backfill known legacy schema strings; malformed snapshots retain unknown metadata. Original snapshots and v1-v13 migration checksums remain unchanged. Failure restores prior schema/guards/user_version; a prior schema plan rejects the newer database. WAL/FULL and native SQLx SQLite linkage stay unchanged.",
     14   "compatibility": "The pre-release storage API gains query/submission types, one required draft query method and command/outcome enum variants. Downstream exhaustive matches and draft-store adapters require the ordered producer adoption. Legacy unscoped draft JSON omits the optional scope and remains byte-identical. Existing Prepare IDs and wire bytes remain unchanged. Public package identity, dependency versions and verification thresholds stay unchanged.",
     15   "verification": ["validated serde and redacted diagnostics", "Memory/SQLite exact and conflicting replay with unchanged supplied digest", "later-save replay and fresh stale-CAS rejection", "simultaneous save/submit and duplicate submissions", "every intermediate insert/receipt fault rolls back", "lost callback and reopened durable receipt", "migration forward and rollback with old-plan refusal", "full current affected profiles, API review, coverage and workspace/release preflight"],
     16   "non_goals": ["application schema policy", "signing authorization", "new service host", "physical power-loss or device qualification", "signed release", "deferred platforms"]
     17 }