deviations.toml (51658B)
1 schema_version = 1 2 architecture_id = "radroots.crates.release.v1" 3 4 [[deviation]] 5 id = "RCRV1-DEV-023" 6 date = "2026-09-22" 7 status = "closed" 8 approval = "Explicit user authorization covers necessary owning-repository repairs, verified checkpoints and non-force publication." 9 affected_steps = ["163", "173", "178"] 10 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sync", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk"] 11 source_evidence = ["Sync adapters collapse the canonical typed capacity error before the host can classify signing or delivery persistence failures.", "SQLite startup and migration adapters similarly discard SQL capacity before SDK report conversion."] 12 replacement_action = "Preserve capacity through existing Sync and startup adapters under storage_capacity_propagation.v1.json, without changing ownership or effect semantics." 13 verification = ["Exercise actual orchestration before and after durable effects with capacity faults and preserved original requests and receipts.", "Verify startup SQL and I/O classification, actual bounded migration failure, unchanged fallback errors and redacted SDK reports.", "Qualify additive API, unchanged coverage gates, portable profiles, full workspace and release preflight."] 14 unresolved_risk = "Typed capacity classification, actual owner regressions, additive API, unchanged coverage gates and complete workspace qualification passed. Consumers still reconcile prior effects; classification grants no eviction or automatic retry authority." 15 normative_architecture_change = false 16 adr_required = false 17 closure_evidence = [ 18 "Sync preserves typed capacity without changing original operation, claim, signer or delivery evidence. Actual before/after faults prove no false success or extra signer/network calls.", 19 "Startup and migration preserve SQL capacity and typed I/O distinctions through the redacted SDK report. Actual bounded SQLite migration failure retains original version and data and retries the pending suffix.", 20 "Three additive variants in non-exhaustive public enums, no removals or umbrella API changes. No schema, SQL policy, transaction, durability, dependency or limit changes.", 21 "All45 coverage gates pass unchanged thresholds. Three affected packages have fresh coverage;42 unchanged package-source reports retain provenance. Complete workspace, minimal profiles, portable, preflight and explicit native/WASM generators pass.", 22 ] 23 24 [[deviation]] 25 id = "RCRV1-DEV-022" 26 date = "2026-09-22" 27 status = "closed" 28 approval = "Explicit user authorization covers necessary owning-repository repairs, verified checkpoints and non-force publication." 29 affected_steps = ["158", "163"] 30 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite"] 31 source_evidence = ["The actual bounded SQLite capacity regression retains the acknowledged draft but collapses SQLITE_FULL into BackendUnavailable.", "Separate SQL adapters erase the same classification at authored, atomic, event, journal, outbox, projection and private-artifact boundaries."] 32 replacement_action = "Preserve bounded capacity classification through the existing storage SPI as governed by storage_capacity_errors.v1.json; keep transactional uncertainty and all original ownership and retention rules." 33 verification = ["Actual SQLITE_FULL preserves acknowledged drafts and unresolved submission source without a success receipt.", "Primary and extended numeric database codes and typed I/O capacity failures are classified without raw diagnostic leakage; unrelated failures retain existing fallbacks.", "Review additive API and preserve coverage thresholds, full workspace, portable and release checks."] 34 unresolved_risk = "Typed capacity classification, actual owner regressions, additive API, unchanged coverage gates and complete workspace qualification passed. Consumers still reconcile prior effects; classification grants no eviction or automatic retry authority." 35 normative_architecture_change = false 36 adr_required = false 37 closure_evidence = [ 38 "Actual bounded SQLITE_FULL retains the acknowledged draft, reports no successful save, and permits exact later retry. Atomic submission failure retains the original source without successful association.", 39 "Primary and extended database capacity codes and typed I/O capacity/quota failures become one redacted error. Unrelated failures remain generic. No operation ID, transaction, receipt, durability policy, schema or limit changes.", 40 "The storage non-exhaustive error enum gains one variant; SQLite, SDK and umbrella public API snapshots are unchanged.", 41 "Both changed packages have fresh coverage and all 45 gates retain their existing thresholds. Unchanged package-source reports retain provenance. Full workspace, portable, contracts, preflight and explicit native/WASM generators pass.", 42 ] 43 44 [[deviation]] 45 id = "RCRV1-DEV-021" 46 date = "2026-09-22" 47 status = "closed" 48 approval = "Explicit user authorization covers required shared-owner repairs, verified checkpoints and non-force integration publication." 49 affected_steps = ["158", "163", "178"] 50 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk"] 51 source_evidence = ["Actual cancellation regression reproduces a stranded RESTORING state after dropping finalization; later close drains pools but cannot release writer authority.", "The SQLite owner already implements verified staging and close-before-replacement restore with durable marker recovery.", "StorageReliability and SDK Operations expose restore metadata transitions but cannot invoke these actual owner operations."] 52 replacement_action = "Expose existing owner staging and finalization through the bounded capability governed by storage_restore_capability.v1.json; repair abandoned restore-close ownership through a private attempt guard, and retain application restore and historical-delivery policy with the host." 53 verification = ["Cancellation retains the active writer until explicit close drains both pools; close then releases authority and unchanged live state reopens.", "Qualify real SPI and SDK restore round trips, unchanged live state during staging, exact restored data and close/reopen behavior.", "Refuse unsupported, closed, read-only, conflicting, malformed and unconfigured operations with bounded path-free errors; preserve existing evidence.", "Review generated additive API and pass affected/minimal checks, unchanged coverage gates, full workspace, portable and release preflight."] 54 unresolved_risk = "Owner and SDK restore, cancellation recovery, additive API, unchanged coverage, full workspace, portability and preflight passed. The host still owns identity, media and durable historical-delivery fencing. No automatic delivery or release qualification is implied." 55 normative_architecture_change = false 56 adr_required = false 57 closure_evidence = [ 58 "Actual SPI and SDK staging preserve live changes; finalization closes the owner and explicit reopen restores exact historical draft IDs and bytes. Unsupported metadata-only backends, closed and read-only owners, malformed members, missing configuration and future formats refuse without leaking paths.", 59 "The initial cancellation regression reproduced a stranded restoring state. A private attempt guard now retains writer authority and closed admission after cancellation while allowing explicit close to drain both pools. Held runtime and protected connections prevent early writer release; the final close and reopen preserve live state.", 60 "Public API additions contain only the bounded restore error and staging/finalization methods. Concrete owner signatures, backup errors, manifests, schema, dependencies and filesystem replacement algorithms remain unchanged.", 61 "All 45 required coverage gates pass unchanged 90 percent thresholds. Three affected packages are freshly measured; 42 unchanged package-source reports retain provenance. No coverage exclusion was added.", 62 "Affected/minimal profiles, full workspace check/tests/Clippy, Rustdoc, catalog, contracts, architecture, API boundaries, graph, portability, preflight and explicit native/WASM generators passed. Final metadata checks revalidate this closure before publication.", 63 ] 64 65 [[deviation]] 66 id = "RCRV1-DEV-020" 67 date = "2026-09-22" 68 status = "closed" 69 approval = "Explicit user authorization covers required shared-owner repairs, verified checkpoints and non-force integration publication." 70 affected_steps = ["158", "163", "178"] 71 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk"] 72 source_evidence = ["SQLx 0.9 returns dropped pooled connections asynchronously, pinging the worker before returning its permit.", "The canonical SQLite owner has four connections per member, so a different connection can inspect or snapshot before earlier cancelled work settles.", "The existing backup SPI cannot establish that all earlier owner work has settled before related host inventory."] 73 replacement_action = "Add the bounded owner-settling capability governed by storage_backup_capability.v1.json; retain all runtime and protected pool permits before returning, while the host separately excludes new commands." 74 verification = ["Held connections prevent early success across both members; cancelled settling releases permits and can retry.", "Abandoned transactions settle their owner rollback before later inventory; committed state remains observable.", "Qualify SDK delegation, unsupported and closed owners, API compatibility, unchanged coverage thresholds and complete workspace/preflight."] 75 unresolved_risk = "Owner, SDK, additive API, unchanged coverage, full workspace, portability and preflight qualification passed. The host must retain its own write exclusion; settling is not a snapshot or an ongoing reservation." 76 normative_architecture_change = false 77 adr_required = false 78 closure_evidence = [ 79 "Canonical SQLite settles all runtime and protected connections before related host inventory. Cancellation releases acquired permits, and a remaining busy protected connection prevents success. Abandoned transactions finish rollback and committed state remains observable.", 80 "SDK delegation, unsupported memory and closed owners pass affected all-feature and minimal checks. The public API review contains only additive settling methods and no removals; backup schemas, manifests, dependencies and pool configuration are unchanged.", 81 "All 45 required package coverage gates pass unchanged 90 percent thresholds. The three affected packages were freshly measured; 42 unchanged package-source measurements retain prior provenance.", 82 "Full workspace check, tests and all-feature Clippy, documentation, catalog, contracts, architecture, DTO/API boundaries, dependency graph, portability, release preflight and both explicitly selected SDK generators pass. Final contract checks revalidate this closure metadata before publication.", 83 ] 84 85 [[deviation]] 86 id = "RCRV1-DEV-019" 87 date = "2026-09-12" 88 status = "closed" 89 approval = "Explicit user authorization covers necessary shared-owner prerequisites, verified checkpoints and non-force origin/master publication." 90 affected_steps = ["158", "163", "173", "178"] 91 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite"] 92 source_evidence = ["Composite submission accepts only ready/queued drafts, whose payload is correctly immutable.", "A caller must durably capture an operation before its prerequisites complete without falsely marking the draft ready or relaxing queued-payload freezing."] 93 replacement_action = "Implement the explicit waiting constructor and compatibility contract in contracts/architecture/decisions/authored_draft_submission.v2.json using the existing transaction and receipt owners." 94 verification = ["Preserve the original constructor, exact ready serialization, all capture invariants and queued-payload freezing.", "Qualify waiting-state replay, source CAS, every transaction fault, prerequisite progress and reopened receipt against Memory and SQLite.", "Pass affected profiles, API freshness, unchanged coverage thresholds and workspace/release preflight before publication."] 95 unresolved_risk = "Owner, SDK, exact API, unchanged coverage, full workspace, generator and release-preflight qualification pass. Each application still owns readiness policy and exact adoption; deferred device and signed-release scope is unclaimed." 96 normative_architecture_change = false 97 adr_required = false 98 closure_evidence = [ 99 "The original ready constructor and wire fields are unchanged. Explicit waiting construction shares all source, author, scope, time, revision and unsent-operation validation; there is one additive public constructor and no API removals.", 100 "Memory and SQLite prove replay after prerequisite progress, later source edits and lost callbacks; changed full requests conflict even when the composite digest is unchanged. Fresh requests still obey source CAS.", 101 "The real SQLite harness covers64 before/after record windows across queued and all three waiting stages, plus actual COMMIT failure, abandoned precommit, SQLITE_FULL and concurrent save/submission. No new schema, connection, transaction or queued-payload mutation is introduced.", 102 "Affected owner tests303, actual SDK tests119 and explicit memory/serde tests146 pass without ignored tests. Full workspace check/test/clippy, Rustdoc, contracts, architecture, DTO/API boundaries, dependency graph, governed portable targets and preflight pass.", 103 "All45 required coverage reports pass unchanged90% thresholds. Storage, SQLite, Sync and SDK were freshly measured;41 source-identical measurements retain their original evidence identities. Both SDK generator opt-ins were explicitly selected and passed current frozen-output/freshness assertions.", 104 ] 105 106 [[deviation]] 107 id = "RCRV1-DEV-018" 108 date = "2026-09-10" 109 status = "closed" 110 approval = "Standing user authorization covers all necessary shared-owner prerequisites, verified commits and non-force publication through RCLD-TERA-100." 111 affected_steps = ["158", "163", "173", "178", "207"] 112 spec_anchors = ["contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sync"] 113 source_evidence = ["The current shared host has immutable draft append CAS and authored Prepare, but no typed transaction joining them.", "The unfiltered draft-head Vec can fail wholesale on a foreign or corrupt snapshot and offers no continuation."] 114 replacement_action = "Implement contracts/architecture/decisions/authored_draft_submission.v1.json within existing storage, SQLite and Sync ownership for C054/P054, before ordered consumer adoption." 115 verification = ["Qualify typed exact replay, atomic rollback/reopen, concurrent save/submit, bounded isolated pages and forward migration compatibility.", "Review public enum/trait additions and pass affected profiles, unchanged coverage, workspace and release preflight."] 116 unresolved_risk = "Current owner, SDK, API, unchanged coverage and complete workspace/release-preflight qualification pass. Application schema policy and ordered consumer adoption remain with the application; deferred platform, physical-device and signed-release qualification are not claimed." 117 normative_architecture_change = false 118 adr_required = false 119 closure_evidence = [ 120 "Memory and real SQLite qualify stable author/command identity, complete semantic comparison independent of caller digest, replay before CAS after later edits, distinct intentional submissions and ordinary Prepare resumption.", 121 "SQLite qualifies sixteen before/after record fault windows, abandoned precommit, actual COMMIT failure, capacity exhaustion, concurrent save/submit, lost callback, reopen, read-only and explicit close.", 122 "Bounded scoped pages isolate corrupt metadata/payloads, preserve legacy unscoped bytes and enforce count and byte budgets. The reference backend uses at most limit+1 scratch heads and scans1000 reversed records without losing revisions or continuation.", 123 "Runtime14 migrates atomically without rewriting original snapshots or historical checksums. The actual prior13ac binary rejects14 in read-only and writable modes with both database files unchanged.", 124 "Reviewed pre-release trait/enum additions and the pure Sync preparation helper pass current owner, SDK, full workspace, Rustdoc, contract, dependency, portable and release-preflight gates. All45 required coverage reports pass unchanged90% thresholds with explicit retained-measurement provenance.", 125 ] 126 127 [[deviation]] 128 id = "RCRV1-DEV-017" 129 date = "2026-09-10" 130 status = "closed" 131 approval = "Explicit user authorization covers necessary shared-owner prerequisites, verified commits and non-force source publication." 132 affected_steps = ["157", "174", "204"] 133 spec_anchors = [ 134 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", 135 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sync", 136 ] 137 source_evidence = [ 138 "Shared sync rejects contract-invalid signed observations before the host can choose verified-only retention.", 139 "Shared visibility selects replacement heads only from Visible records, allowing an older visible payload to survive a newer retained signature-verified head.", 140 ] 141 replacement_action = "Implement contracts/architecture/decisions/verified_event_heads.v1.json: explicit default-reject verified retention and canonical head selection before payload visibility, without adding product policy to shared storage." 142 verification = [ 143 "Reproduce stale fallback and verify raw, malformed, signature, tie, author, deletion-before-target, order, stage advancement and memory/SQLite parity cases.", 144 "Review additive public API and pass affected owner and SDK tests, unchanged coverage thresholds, workspace contracts and release preflight.", 145 ] 146 unresolved_risk = "Owner, backend, SDK, additive API, unchanged coverage and workspace qualification pass. Verified heads intentionally suppress older visible payloads; only opt-in policies retain contract-invalid signed observations. No external release or deferred platform qualification is claimed." 147 normative_architecture_change = false 148 adr_required = false 149 closure_evidence = [ 150 "The original stale-fallback regression now passes with raw-to-verified advancement, canonical ties, empty coordinates, reversed arrival order and author-authorized deletion-before-target.", 151 "Real signed sync ingestion preserves default rejection and rejects bad signatures before host retention; opt-in failures stay Verified and valid later admission advances at the same raw count.", 152 "Memory and reopened SQLite return matching admission receipts, visibility snapshots and bounded queries. All isolated owner and SDK lanes pass; only the defaulted retention method and closed decision are additive API changes.", 153 "Fresh storage, SQLite, sync and SDK coverage and all 45 required reports/aggregate pass with unchanged thresholds, together with complete workspace, portable and release-preflight gates.", 154 ] 155 156 [[deviation]] 157 id = "RCRV1-DEV-016" 158 date = "2026-09-10" 159 status = "closed" 160 approval = "Standing user authorization covers necessary shared-owner repairs, verified checkpoint commits and non-force producer publication." 161 affected_steps = ["201"] 162 spec_anchors = [ 163 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport_nostr", 164 ] 165 source_evidence = [ 166 "The concrete REQ asks for 1000 events, but exactly 1000 followed by EOSE is currently normalized as Complete.", 167 "After a 500-event first page, another 500 equal-time events produce Complete with no cursor despite additional capped or older history.", 168 ] 169 replacement_action = "Implement contracts/architecture/decisions/nostr_fetch_windows.v1.json within the existing adapter: partial capped coverage, lossless paging of received candidates and finite explicit older-window continuation." 170 verification = [ 171 "Reproduce capped EOSE false-completion, then verify ordinary and capped ties, duplicate relays, older history, malformed/boundary inputs and scoped continuation through injected and loopback sources.", 172 "Pass affected package and SDK checks, unchanged public API and coverage thresholds, full workspace and required release-preflight gates before publication.", 173 ] 174 unresolved_risk = "Current owner, SDK, API, coverage and workspace gates pass. A saturated timestamp can still hide additional events; the partial yield and explicit older continuation never claim lossless or global-history recovery." 175 normative_architecture_change = false 176 adr_required = false 177 closure_evidence = [ 178 "The false-complete regression now passes with 501, 1000 and 1001 equal-time events, cross-relay deduplication, explicit older continuation and canonical scoped cursor rejection.", 179 "A real WebSocket relay returns exactly 1000 signed same-time events and EOSE; both received pages and the explicit older query pass without reconnect backoff or automatic boundary skipping.", 180 "Malformed/out-of-bound and zero-time cases fail closed. Public transport and SDK APIs remain byte-identical. Fresh affected coverage, all 45 reports and aggregate, complete workspace and release-preflight checks pass without threshold changes.", 181 ] 182 183 [[deviation]] 184 id = "RCRV1-DEV-015" 185 date = "2026-09-09" 186 status = "closed" 187 approval = "Standing user approval of the reviewed refactor and necessary shared-owner prerequisites, including verified producer commits and non-force publication." 188 affected_steps = ["201"] 189 spec_anchors = [ 190 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sync", 191 ] 192 source_evidence = [ 193 "PullReceipt intentionally retains the final per-target outcome, so a later complete page replaces an earlier partial or failed page.", 194 "FetchPage permits missing target outcomes; a complete page marker alone cannot prove every requested target supplied complete evidence.", 195 ] 196 replacement_action = "Add bounded cumulative per-target summaries under contracts/architecture/decisions/pull_target_evidence.v1.json, preserving final-page API semantics and legacy receipts as unknown evidence." 197 verification = [ 198 "Exercise incomplete/complete ordering, omitted outcomes, multiple targets, exact limits, termination and compatible serialization through the real shared engine and SDK delegation.", 199 "Qualify current package/workspace, API, feature, coverage and release-preflight surfaces before publication and consumer adoption.", 200 ] 201 unresolved_risk = "Current shared sync, SDK, workspace, API and unchanged coverage gates pass. Summary completeness remains scoped to returned pages and must be combined with pull termination; no global-history or new release authority is claimed." 202 normative_architecture_change = false 203 adr_required = false 204 closure_evidence = [ 205 "The reproduced partial-then-complete regression passes while final outcomes remain unchanged; all actual incomplete states, missing outcomes, multiple targets, 64 targets and 1,000 pages are exercised.", 206 "Legacy and malformed serialization, source/page/deadline/cancellation cases, and actual SDK cumulative-evidence delegation pass with the supported feature profiles.", 207 "Generated shared API retains every previous declaration, SDK API is byte-identical, fresh sync/SDK coverage and all 45 reports/aggregate pass, and the full workspace and release-preflight lanes pass.", 208 ] 209 210 [[deviation]] 211 id = "RCRV1-DEV-013" 212 date = "2026-09-09" 213 status = "closed" 214 approval = "Standing user approval of the complete reviewed refactor and its necessary same-owner producer repairs." 215 affected_steps = ["201"] 216 spec_anchors = [ 217 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport_nostr", 218 ] 219 source_evidence = [ 220 "Current source.rs starts each buffered relay batch with a fresh timeout although the public fetch contract promises one absolute request deadline.", 221 "Per-relay event counts are bounded, but aggregate raw JSON bytes and parse inventory are not explicitly capped before shared candidate collection; relay.rs inherits dependency-default wire limits.", 222 ] 223 replacement_action = "Repair the current concrete adapter within its existing bounded-fetch charter, using contracts/architecture/decisions/nostr_fetch_bounds.v1.json. This is a current source repair, not a reopening or replacement of historical release qualification." 224 verification = [ 225 "Deterministic limit, aggregate competition, queued-deadline and retained partial-outcome regressions plus bounded loopback source tests.", 226 "Canonical package/workspace checks, contracts, architecture, public API review and the unchanged affected-package coverage requirement.", 227 ] 228 unresolved_risk = "Current package and workspace verification, byte-identical public API, all 49 required coverage reports and release preflight pass on the qualified source. Per-target partial/cancelled evidence is bounded; no global-history, power-loss, external release, device or new-platform qualification is claimed." 229 normative_architecture_change = false 230 adr_required = false 231 closure_evidence = [ 232 "Fresh transport coverage passes all four unchanged thresholds; the public API is byte-identical to its baseline.", 233 "All 49 required coverage reports and the aggregate pass, together with workspace check, tests, Clippy, Rustdoc, contracts, freshness, dependency graph, portable checks and release preflight.", 234 "Deterministic maxima and aggregate budget tests plus real loopback queued-deadline, mixed-relay, oversized-wire and cancellation regressions pass.", 235 ] 236 237 [[deviation]] 238 id = "RCRV1-DEV-014" 239 date = "2026-09-09" 240 status = "closed" 241 approval = "Explicit user authorization to repair required repository coverage and release-preflight blockers while preserving quality thresholds and deferred qualification scope." 242 affected_steps = ["315"] 243 spec_anchors = [ 244 "contracts/crates/release_v1/radroots_crates_release_v1.toml#quality_policy.coverage", 245 ] 246 source_evidence = [ 247 "Current release preflight requires all current coverage-policy package reports and their aggregate; the aggregate is absent and the existing xtask line/branch measurements are below policy.", 248 "The advisory, bounded-process and safe-artifact contracts name executable self-tests, but Cargo tests check their decision metadata without executing the complete CLI self-test suites.", 249 "The detailed coverage scope mapper assumes crates/<package>/src even for xtask, whose source is tools/xtask/src; this selects no detailed functions or regions and reports empty perfect percentages.", 250 "A deterministic malformed RustSec affected-object regression reproduces a panic when the functions member is absent; checked optional lookup must return the existing InvalidReport error instead.", 251 "Workspace-only coverage cleanup leaves orphan xtask executables under debug/build/xtask with older source maps. A measured one-line parser shift adds stale branch/region records; reset the owned coverage build tree before current collection instead of filtering those records or trusting contaminated metrics.", 252 "Retained gate and platform validators lack isolated argument, canonical-authority, inventory and result-encoding coverage. Extract those private transformations without changing pinned historical contracts or invoking their external qualification commands.", 253 "Synthetic parsed ELF fixtures reproduce acceptance of 32-bit and big-endian binaries despite the existing elf64_little_endian_x86_64_execute_or_pie contract. Enforce the existing class and byte-order requirements alongside machine, entrypoint and executable-segment validation.", 254 "Normalized Gradle graph validation is coupled to descriptor-bound admission that rejects changed projections before their structural checks. Isolate the existing private structural validator, preserve its call order, and exercise malformed graph identity, lineage and artifact bindings without fabricating admitted filesystem evidence.", 255 "Gradle projection metadata and process-receipt bindings share the same admitted-projection short circuit as graph structure. Isolate their private validator without changing check order or errors so receipt, raw-source, count and normalization bindings can be tested with structurally valid inputs.", 256 "Fresh collection succeeds for all 49 required packages, with 47 passing every coverage gate. Runtime paths has 82.407407 percent branch coverage and service SQLite has 89.316239 percent; their other metrics pass. Add focused owner tests for retained directory identity and cleanup, bounded schema catalogs, metadata and migration-history rejection without changing public behavior, policy or historical qualification.", 257 ] 258 replacement_action = "Qualify current required-package behavior through the governed coverage commands, execute omitted existing CLI self-tests, and add narrow owner tests or testability repairs justified by actual uncovered paths. This repairs current qualification and does not reopen historical release or deferred Nix/device gates." 259 verification = [ 260 "Current owned command self-tests and their failure assertions execute from Cargo integration tests with no external provider or Nix access.", 261 "All currently required package reports retain the existing coverage policy; the generated aggregate and release preflight must pass before qualification is complete.", 262 "Relevant Rust, contract, architecture, API, feature and generated-freshness checks remain required.", 263 ] 264 unresolved_risk = "Current macOS aarch64 qualification is complete. Deferred Nix, device, historical release and deployment qualification remain outside this repair; two unchanged opt-in SDK generators are not claimed by the workspace test lane." 265 normative_architecture_change = false 266 adr_required = false 267 closure_evidence = [ 268 "All 49 required package reports pass the unchanged four-metric coverage policy, and the governed aggregate and release preflight pass.", 269 "The full workspace check, test, Clippy and Rustdoc lanes pass, together with catalog, architecture, contracts, DTO freshness, API boundaries, resolved dependency graph and portable checks.", 270 "Runtime-paths and service-SQLite documentation tests pass; generated public API text is byte-identical to each reviewed baseline. Their five changed source files contain test-only additions.", 271 "Cargo tests execute the three complete offline command self-tests. The workspace reports 3816 passing tests and eight ignored entrypoints: six process children exercised by parents and two unchanged opt-in SDK generators outside this lane.", 272 ] 273 274 [[deviation]] 275 id = "RCRV1-DEV-001" 276 date = "2026-07-27" 277 status = "active" 278 approval = "Explicit user correction dated 2026-07-27." 279 affected_steps = [ 280 "015", 281 "016", 282 "017", 283 "018", 284 "019", 285 "020", 286 "021", 287 "022", 288 "023", 289 "026", 290 ] 291 spec_anchors = [ 292 "contracts/crates/release_v1/radroots_crates_release_v1.toml#repositories.lib", 293 "contracts/crates/release_v1/radroots_crates_release_v1.toml#repository_policy", 294 ] 295 source_evidence = [ 296 "The final v1 specification allocates 17 public packages to radrootslabs/lib and 2 to radrootslabs/sdk.", 297 "Both existing repositories have independent histories, workspaces, lockfiles, remotes, and standalone release boundaries.", 298 ] 299 replacement_action = "Retain the two existing standalone repositories; replace import and monorepo-unification work with independent workspace, lockfile, metadata, dependency, and release qualification." 300 verification = [ 301 "Both repository-local architecture validators resolve every spec anchor.", 302 "The synchronized architecture catalog enforces the exact 17/2 ownership partition.", 303 "Each standalone repository owns a required architecture CI adapter over its repository-local command surface.", 304 ] 305 unresolved_risk = "Parent gitlinks cannot advance until the new standalone commits are public-remote reachable under separate authorization." 306 normative_architecture_change = false 307 adr_required = false 308 309 [[deviation]] 310 id = "RCRV1-DEV-010" 311 date = "2026-08-03" 312 status = "closed" 313 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 314 affected_steps = ["201", "215", "269", "294", "301", "313"] 315 spec_anchors = [ 316 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport_nostr", 317 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport", 318 ] 319 source_evidence = [ 320 "The Step 294 downstream matrix proved the former app_rt radroots_net_core consumer had migrated and no current first-party manifest retained an edge to radroots_net.", 321 "Step 301 full workspace qualification proved that the assigned radroots_nostr_runtime Step 215 deletion and radroots_net Step 313 deletion had not been applied even though both removal gates were satisfied.", 322 "Both obsolete packages failed against the final transport boundary when the complete all-feature workspace closure was checked.", 323 ] 324 replacement_action = "Delete radroots_nostr_runtime, its NostrDB runtime adapter, and radroots_net during Step 301 qualification; forbid their package, dependency, alias, feature, and source identities from being reintroduced." 325 verification = [ 326 "Transport-owned tests reject reintroduction of radroots_nostr_runtime, radroots_net, or the NostrDB runtime-adapter feature.", 327 "Workspace-wide source tests reject every removed transport-client identifier without a compatibility exception.", 328 "The full all-target and all-feature workspace qualification compiles without either predecessor package.", 329 ] 330 unresolved_risk = "None for the two removed packages; historical names remain only in governed specifications, migration evidence, and fail-closed regression assertions." 331 normative_architecture_change = false 332 adr_required = false 333 closure_evidence = [ 334 "crates/transport_nostr/tests/workspace_consumers.rs proves both package directories and workspace dependency identities are absent.", 335 "crates/transport_nostr/tests/legacy_quarantine.rs proves release policy and the compatibility ledger no longer classify either package as a retained shim.", 336 ] 337 338 [[deviation]] 339 id = "RCRV1-DEV-008" 340 date = "2026-08-01" 341 status = "closed" 342 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 343 affected_steps = ["153", "155", "171", "179", "226", "288", "293", "313"] 344 spec_anchors = [ 345 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_secrets", 346 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", 347 ] 348 source_evidence = [ 349 "The final radroots_storage_sqlite scaffold can consume radroots_secrets immediately and has no predecessor secret dependency.", 350 "Step 179, not Step 153, owns transfer of the current SDK private database and its encrypted records into canonical SQLite storage.", 351 "Mixed publish-frozen runtime, Nostr-account, SimpleX preview, SDK private-store, Myc, and other external hosts still require predecessor vault/store behavior until their ordered migration steps.", 352 ] 353 replacement_action = "Activate the final radroots_storage_sqlite and SDK dependency edges in Step 153; confine predecessor vault/store imports to exact publish-frozen quarantine packages and the SDK private-store module; Step 179 transfers canonical private storage, Steps 226/288/293 migrate the remaining SDK and downstream consumers, and Step 313 removes every remaining compatibility package and legacy name." 354 verification = [ 355 "Consumer-migration tests enumerate every lib package manifest that still names radroots_secret_vault or radroots_protected_store and reject any unapproved or publishable consumer.", 356 "Storage SQLite package-boundary tests require radroots_secrets and reject all predecessor secret package names.", 357 "SDK source-boundary tests confine predecessor imports to private_store.rs and require the final optional radroots_secrets dependency edge.", 358 "Step 155 release-policy validation keeps every quarantine package non-publishable until its exact removal gate.", 359 ] 360 unresolved_risk = "None; the predecessor packages and all active manifest consumers are absent." 361 normative_architecture_change = false 362 adr_required = false 363 closure_evidence = [ 364 "crates/secrets/tests/consumer_migration.rs rejects every predecessor package directory, workspace dependency, and active manifest reference.", 365 "Step 313 source census confirmed the SDK, Myc, CLI, and library runtime paths use only radroots_secrets and final storage owners.", 366 ] 367 368 [[deviation]] 369 id = "RCRV1-DEV-007" 370 date = "2026-07-30" 371 status = "closed" 372 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 373 affected_steps = ["122", "170", "215", "235", "305"] 374 spec_anchors = [ 375 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport", 376 ] 377 source_evidence = [ 378 "Step 120 migrated canonical adapters and registries to independent EventSource and EventSink contracts.", 379 "Mixed runtime delivery workers still consume predecessor request and receipt models until their ordered RCLD 40 migration.", 380 "The runtime delivery worker also accepts opaque byte payloads, while the final EventSink contract accepts only verified SignedEvent values; deleting the bridge at Step 170 would silently remove a supported private runtime path before sync orchestration owns that decision.", 381 "The standalone publish-frozen SDK still maps user-facing target and satisfaction models into predecessor outbox orchestration until Step 235.", 382 "oss/cli/src/runtime/{config,sync,transport}.rs and oss/radrootsd/src/core/transport_publish.rs still import the predecessor identity aliases and Reticulum target helpers; those standalone repositories are outside the approved crate-surface mutation scope.", 383 ] 384 replacement_action = "Remove the monolithic trait from radroots_transport in Step 122; retain one explicitly named runtime-owned unpublished shim until Step 215 at the sync-orchestration retirement gate, the SDK-local unpublished target/satisfaction mapping until Step 235, and documentation-hidden external-consumer aliases/helpers until the fail-closed package-realistic Step 305 gate." 385 verification = [ 386 "Transport source-boundary tests reject every removed public predecessor name and require the singular runtime-owned shim.", 387 "Release policy keeps runtime and SDK publication disabled while either downstream shim exists.", 388 "Steps 215 and 235 are the exact fail-closed final-removal gates for the remaining runtime and SDK mappings.", 389 "Step 305 rejects publication until oss/cli and oss/radrootsd no longer require the documentation-hidden external-consumer aliases and Reticulum helpers.", 390 ] 391 unresolved_risk = "None; final consumers use TransportId, Target, TargetScope, TargetLabel, and TargetFingerprint directly." 392 normative_architecture_change = false 393 adr_required = false 394 closure_evidence = [ 395 "crates/transport/tests/package_boundary.rs rejects the hidden Reticulum constructors, legacy constant spellings, and prefixed target aliases.", 396 "Step 313 source census confirmed every external-consumer alias and helper is absent after the daemon cutover to final transport identities.", 397 ] 398 399 [[deviation]] 400 id = "RCRV1-DEV-009" 401 date = "2026-08-02" 402 status = "closed" 403 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 404 affected_steps = [ 405 "170", 406 "179", 407 "189", 408 "196", 409 "201", 410 "213", 411 "226", 412 "235", 413 "263", 414 "269", 415 "288", 416 "292", 417 "313", 418 ] 419 spec_anchors = [ 420 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage", 421 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_storage_sqlite", 422 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk", 423 ] 424 source_evidence = [ 425 "The Step 170 first-party census found radroots_event_index consumers in the standalone CLI, SDK, SDK bindings, and indexer repositories.", 426 "The census found radroots_event_store and radroots_outbox consumers in the standalone CLI and SDK, plus active library transport_nostr orchestration scheduled to move in Step 196.", 427 "The census found radroots_runtime_store consumed by the standalone CLI, whose crate cutover is scheduled after the canonical library storage and sync implementations are complete.", 428 "Deleting these packages before their ordered migrations would make the independently buildable first-party repositories unresolvable and would remove the source data needed by the approved one-shot importer.", 429 ] 430 replacement_action = "Keep radroots_event_index, radroots_event_store, radroots_outbox, and radroots_runtime_store as documentation-hidden publish-frozen compatibility packages with no new consumers; port durable behavior into radroots_storage_sqlite through Step 189, remove local transport coupling in Step 196, migrate library/SDK/binding/CLI/indexer consumers in their ordered steps, and delete every remaining package at Step 313." 431 verification = [ 432 "Package manifests carry machine-readable publish-frozen metadata naming the final replacement, deviation, Step 313 removal gate, and prohibition on new consumers.", 433 "A storage-owned quarantine test requires the four packages to remain private and absent from the approved publication inventory.", 434 "Workspace checks and tests prove current migration consumers remain buildable while publication stays frozen.", 435 "Step 313 performs the all-first-party forbidden-name search and final package deletion.", 436 ] 437 unresolved_risk = "None; all four predecessor packages and their active dependency edges are absent." 438 normative_architecture_change = false 439 adr_required = false 440 closure_evidence = [ 441 "crates/storage_sqlite/tests/package_boundary.rs and crates/storage/tests/workspace_consumers.rs reject the four predecessor package identities.", 442 "Step 313 removed the final library packages, SDK runtime/event-index surfaces, and CLI source dependency branch after all standalone consumers migrated.", 443 ] 444 445 [[deviation]] 446 id = "RCRV1-DEV-005" 447 date = "2026-07-28" 448 status = "active" 449 approval = "Explicit user Rust version-policy update dated 2026-07-28 17:47 UTC." 450 affected_steps = [ 451 "013", 452 "019", 453 "020", 454 "021", 455 "022", 456 "023", 457 "024", 458 "025", 459 "026", 460 "305", 461 ] 462 spec_anchors = [ 463 "contracts/crates/release_v1/radroots_crates_release_v1.toml#repositories.lib", 464 ] 465 source_evidence = [ 466 "The prior 1.0.0 and mixed 0.1.0 prerelease crate cohorts were explicitly declared incorrect.", 467 "The user requires every Rust crate in radrootslabs/lib to remain exactly 0.1.0-alpha until further explicit notice.", 468 ] 469 replacement_action = "Pin every workspace package, lockfile entry, and internal Radroots dependency requirement in radrootslabs/lib to 0.1.0-alpha; preserve independent protocol and sibling-repository versions; reject library cohort drift until new explicit authority is recorded." 470 verification = [ 471 "Repository architecture validation rejects any workspace package version other than 0.1.0-alpha.", 472 "Internal Radroots dependency requirements resolve exactly to =0.1.0-alpha.", 473 "Synchronized release specifications record the library cohort independently from the SDK repository version.", 474 ] 475 unresolved_risk = "The prerelease cohort intentionally prevents independent library package version advancement until a future explicit policy change." 476 normative_architecture_change = false 477 adr_required = false 478 479 [[deviation]] 480 id = "RCRV1-DEV-002" 481 date = "2026-07-27" 482 status = "active" 483 approval = "Explicit user correction dated 2026-07-27." 484 affected_steps = ["249"] 485 spec_anchors = [ 486 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots", 487 "contracts/crates/release_v1/radroots_crates_release_v1.toml#repositories.sdk", 488 ] 489 source_evidence = [ 490 "The final v1 specification assigns the radroots facade to the existing sdk repository.", 491 "The approved sequence requires radroots to be the first crate-surface mutation after architecture controls are green.", 492 ] 493 replacement_action = "Scaffold radroots in the sdk repository immediately after Step 014, then execute Steps 250-260 in their original order without repeating the scaffold portion of Step 249." 494 verification = [ 495 "The sdk release policy reserves radroots as an approved local package while publication remains frozen.", 496 "The facade scaffold checkpoint must add radroots only to the sdk workspace and architecture policy.", 497 ] 498 unresolved_risk = "The facade remains non-publishable until the package-realistic Step 305 enablement gate." 499 normative_architecture_change = false 500 adr_required = false 501 502 [[deviation]] 503 id = "RCRV1-DEV-004" 504 date = "2026-07-28" 505 status = "active" 506 approval = "Explicit user coverage-policy update dated 2026-07-28 17:15 UTC." 507 affected_steps = [ 508 "098", 509 "155", 510 "225", 511 "260", 512 "268", 513 "294", 514 "298", 515 "299", 516 "301", 517 "302", 518 "303", 519 "304", 520 "314", 521 ] 522 spec_anchors = [ 523 "contracts/crates/release_v1/radroots_crates_release_v1.toml#quality_policy.coverage", 524 ] 525 source_evidence = [ 526 "The oss/lib codebase is under heavy development during the multi-RCLD refactor.", 527 "The user explicitly replaced the active 100% coverage requirement with a uniform 90% module requirement.", 528 ] 529 replacement_action = "Enforce 90% executable-line, function, region, and branch coverage for every required oss/lib crate; retain only no-branch-record exceptions; defer restoration of 100% until an explicit future contract update after refactor stabilization." 530 verification = [ 531 "Contract validation rejects any base coverage dimension other than 90% or disabled required branches.", 532 "Coverage policy-gate tests prove values below 90% fail and values at or above 90% pass.", 533 "The required-crate inventory remains complete and crate-specific numeric thresholds below 90% remain forbidden.", 534 ] 535 unresolved_risk = "A 90% development gate admits untested paths that a later 100% gate would reject; the final restoration remains intentionally unscheduled pending explicit authority." 536 normative_architecture_change = false 537 adr_required = false 538 539 [[deviation]] 540 id = "RCRV1-DEV-011" 541 date = "2026-08-03" 542 status = "closed" 543 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 544 affected_steps = ["225", "226", "248"] 545 spec_anchors = [ 546 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_geonames", 547 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk", 548 ] 549 source_evidence = [ 550 "The standalone SDK manifest and GeoNames module still resolve radroots_geocoder and its test-fixture feature while the final provider package is implemented in this independently versioned repository.", 551 "The legacy package has no in-repository consumer, is publish disabled, and is already excluded from the exact release-v1 public package inventory.", 552 "Deleting the package at Step 225 would make the independently buildable SDK repository unresolvable before its ordered manifest and API cutover begins at Step 226.", 553 ] 554 replacement_action = "Keep radroots_geocoder as a documentation-marked, machine-classified publish-frozen bridge with no new consumers, features, contracts, or behavior; migrate the standalone SDK to radroots_geonames beginning at Step 226 and delete the bridge at the SDK retirement gate in Step 248." 555 verification = [ 556 "The predecessor manifest names radroots_geonames as its replacement, RCRV1-DEV-011 as authority, and Step 248 as the exact removal gate.", 557 "GeoNames package quarantine tests require the predecessor to remain private and absent from the approved publication inventory while the SDK source census remains non-empty.", 558 "Step 248 must reject every remaining package, dependency, feature, import, and error-adapter reference to radroots_geocoder before deletion.", 559 ] 560 unresolved_risk = "None; the SDK consumes radroots_geonames and the predecessor package is absent." 561 normative_architecture_change = false 562 adr_required = false 563 closure_evidence = [ 564 "crates/geonames/tests/package_boundary.rs rejects the superseded package directory and release-policy identity.", 565 "The SDK Step 248 checkpoint removed every radroots_geocoder dependency, feature, import, and error-adapter reference.", 566 ] 567 568 [[deviation]] 569 id = "RCRV1-DEV-012" 570 date = "2026-08-03" 571 status = "closed" 572 approval = "All code-review recommendations and the full multi-RCLD implementation sequence were explicitly approved by the user." 573 affected_steps = ["279", "282", "283"] 574 spec_anchors = [ 575 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport", 576 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_transport_nostr", 577 "contracts/crates/release_v1/radroots_crates_release_v1.toml#package.radroots_sdk", 578 ] 579 source_evidence = [ 580 "The first-party mobile compile gate proved that its real relay-backed identity, profile, and post operations had no equivalent after the initial shared-engine bridge cutover.", 581 "The generic source request could bound pages and targets but could not express event kind, author, or event-time constraints required for correct profile and feed queries.", 582 "Restoring the retired parallel runtime or accepting client-side filtering after page truncation would violate the final SDK and transport ownership model.", 583 ] 584 replacement_action = "Before qualifying the mobile artifact, add bounded transport-neutral fetch selectors, translate them in the concrete Nostr adapter, complete SDK-owned explicit local-signing and Nostr composition, and map the mobile presentation contract over those SDK operations without restoring direct lower-package dependencies." 585 verification = [ 586 "Transport selector construction rejects oversized, duplicate, and reversed-range inputs and binds selectors into page validation.", 587 "The Nostr adapter applies kind, author, and time constraints remotely and defensively filters returned events before page bounds.", 588 "The shared-engine SDK and mobile integration gates must pass before Steps 282 and 283 are marked complete.", 589 ] 590 unresolved_risk = "None; the shared-engine and mobile qualification checkpoints completed with the final selector and SDK ownership model." 591 normative_architecture_change = false 592 adr_required = false 593 closure_evidence = [ 594 "crates/transport/tests/source_contract.rs verifies bounded canonical selector construction and request binding.", 595 "crates/transport_nostr/src/source.rs tests remote selector translation and defensive result filtering before page bounds.", 596 "Steps 282 and 283 qualified the SDK-owned signing, Nostr composition, and mobile presentation bridge without lower-package ownership leakage.", 597 ]