Ship the SR-003 schema bump: jmanifest_version 2
CI / fmt, clippy, test (push) Failing after 1m22s
CI / static musl binary (push) Has been skipped
CI / advisories and licences (push) Successful in 26s

Moves the exchange envelope to version 2 in lockstep with the truth file's
schema_version, per SR-003's requirement that breaking changes be batched and
ship together rather than piecemeal. The plugin had already moved to
schema_version 2; the server declaring 1 while accepting the new fields
defeated the point of having a version at all.

Flag day, not dual-accept (JR-003): version 1 is now rejected outright. All
three components are pre-release, and a v1 read path would be the one nobody
exercises, so it is the one that would rot while being dragged through every
later change to the reader. A pipeline still emitting v1 is incompatible until
updated — stated plainly rather than papered over with a shim nobody tests.

scenes become objects carrying belief and route (extraction AR-017) instead of
float pairs. Belief is bounded to [0, 1] rather than merely stored: §5a's
Threat 1 argument rests on every accepted value being bounded, and an unbounded
float is a 64-bit channel however harmless it looks. route is a closed enum, so
an invented value cannot be stored.

UR-018 is the requirement with the trap in it, and the reason content_id.rs is
untouched by this commit: belief is a producer-side estimate that may
legitimately differ between pipeline versions for identical timings, so
including it in the canonical form would give two servers different ids for the
same content — the exact failure mode §9a quantises centiseconds to avoid,
reintroduced one field along. It replicates as an attribute, exactly as
audio_signature does. The golden vector still passes unchanged, which is the
evidence rather than the claim.

191 tests. UR-015..018 move from Planned to Done; coverage 24/32 (75%).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

TRACES: UR-014, UR-015, UR-016, UR-017, UR-018 | SR-003
This commit is contained in:
2026-07-31 09:13:14 +02:00
co-authored by Claude Opus 5
parent c73f417d45
commit 88c7264094
12 changed files with 494 additions and 179 deletions
+18 -4
View File
@@ -39,6 +39,12 @@ Implemented:
- §8 Rust + Axum + SQLite, single serialized writer, in-process job queue
- §9a content addressing (`content_id`), computed on upload
**Schema version 2** (SR-003). `jmanifest_version` moved to 2 in lockstep with
the truth file's `schema_version` — breaking changes are batched and ship
together across all three repos. It is a **flag day**: version 1 is rejected
outright rather than carried alongside, because a v1 read path would be the one
nobody exercises and so the one that rots.
Reconciled with the system spec (see `docs/requirements.md` for the detail):
- **`anneal_sec` removed.** Withdrawn upstream by AR-012/AR-013 — presence now
@@ -48,6 +54,14 @@ Reconciled with the system spec (see `docs/requirements.md` for the detail):
carrying `anneal_sec` is now a hard `400`, not silently ignored: it was
produced by a pipeline whose window semantics differ from what this server
assumes.
- **Windows carry belief and route.** `scenes` are objects rather than float
pairs: `{ "start", "end", "belief", "route" }`, where belief is the posterior
that justified the claim and route is `live`/`deferred`/`pooled`. Both are
**excluded from `content_id`** — belief is a producer-side estimate that may
differ between pipeline versions for identical timings, so hashing it would
give two servers different ids for the same content. `src/content_id.rs` is
unchanged by the bump and its golden vector still passes, which is the
evidence rather than the claim.
- **Audio signature: the 120 s rule now matches both producers.** An earlier
draft of §3 allowed a shortened window for items under 150 s; that conflicted
with `scene-actor-extraction` IR-007 and was the weaker rule, since a
@@ -110,7 +124,7 @@ curl -sX POST -H 'content-type: application/json' -d '{}' \
## Tests
```sh
cargo test # 189 tests
cargo test # 191 tests
cargo deny check # advisories, licences, bans, sources
scripts/traceability-gate.sh # requirement coverage
```
@@ -123,9 +137,9 @@ git submodule update --init --recursive
It reports coverage against [`docs/requirements.md`](docs/requirements.md),
flags orphan tags (an ID no register defines), and fails on a >100% ratio — the
signal that the computation itself is broken. Currently **23/32 (71.9%)**; the
untraced nine are UR-007 (plugin-side), UR-008 (federation) and UR-015..018 (the
pending SR-003 bump), none of which is implemented yet.
signal that the computation itself is broken. Currently **24/32 (75%)**; the
untraced remainder is UR-007 (plugin-side) and UR-008 (federation), neither of
which is implemented here yet.
Unit tests per module, plus two integration suites: