Bind query evidence and Python imports to proven index state #264

Merged
buildagent merged 3 commits from fix/review-followthrough-20260911 into master 2026-09-11 15:57:11 +02:00
Member

Queries could combine different SQLite snapshots while reporting only Git provenance, and negative answers did not disclose working-tree changes beyond indexed content. This change adds transactional content identities, evidence from the snapshots actually read, RPC propagation, content-bound cursors, compound-query consistency checks, and bounded freshness observations.

Python imports resolve by proven module and export origin, including aliases, relative imports and conservative re-exports. Ambiguous or shadowed origins remain unresolved. Schema 67 repairs existing Python bindings; actual Flask and Django v65 databases upgrade to the same bindings as fresh indexes. The untyped storage.request.COOKIES chain in #250 remains outside proven type flow.

Executable build identities are unified, archive member versions and installer staging are verified, and routing timing assertions use deterministic work counts. Windows smoke stages the four release binaries in a fresh directory; unexpected executables within an archive are still rejected.

Corpus effects

All nine pinned repositories were compared against clean master 017c6d8 using occurrence-aware joins and source adjudication. Reference populations are unchanged; all seven non-Python repositories are bind-for-bind unchanged.

Corpus Correct gains False bindings removed Correct losses Conditionally correct losses Corrected targets
Django 1715 1126 74 76 2
Flask 13 10 2 0 0

Correct losses include composed exports, extra import roots and object/ancestry flows not modeled here. Conditional losses involve runtime proxies, GIS configuration and task decorators. These accepted coverage losses are recorded alongside the gains. Historical #247 residuals remain tracked in #263; no rerun of that historical census is claimed.

The approved structural, resolver-stage and tier-3 records were generated by the existing measurement writers, with generation identities, categorized diffs and positive controls. Flask resolves one additional reference overall; Django resolves 439 more. The structural exception and complete target-movement review are documented in the records.

Measurement records

Corpus response budgets record snapshot evidence costs of +816/+912/+840 tokens for C#/Flask/Rust and freshness costs of +71/+0/+70. Attribution preserves the previous history and separates inherited record drift from these exact field costs. Questions, calls, answer quality, fallback counts and competitor populations are unchanged. The new recorded totals are 10645/10311/9976; fresh verification measured 10651/10304/9970.

Ruby package cost was measured in isolation under schema 67 / package 0.6.0: vm_step 26439909, fullscan_step 584758, sort 297, autoindex 20745, wall ratio 135%. These remain inside the previous bands. A subsequent verification also passed. All tolerance multipliers, the 60-token response drift allowance, reserve policy and existing plugin benchmark records are unchanged.

Validation

  • On 296cc58, native Windows CI passed workspace tests, all eight staged shipped-set smoke checks and all six release-worker smoke checks. Linux CI passed fmt, clippy, MSRV, windows-gnu, ABI32/wasm, deny, private-item docs, complete workspace and full daemon transport.
  • On 022d665, release structural/stage/tier-3/Ruby gates passed: 26 tests. Real-corpus benchmarks and attribution checks passed: 7 tests. Formatting and diff checks passed. Full PR CI passed on 022d665: native Windows (including staged shipped-set smoke 8/8 and release-worker smoke 6/6), complete Linux workspace, full daemon transport, corpus, formatting, lint, compatibility, dependencies and documentation. Corpus CI measured 10654/10312/9970 response tokens, inside the unchanged tolerances.
  • Complete earlier local workspace: 3762 passed, 43 ignored, 347 test groups. Full daemon-backed MCP suite passed.
  • Release precision gate passed 7/7 against its declared synthetic decoys; it covers zero corpus repositories.
  • 32 mutation checks killed their intended tests; source restoration was verified by checksum.
  • Linux release archive smoke passed 8/8; installer source/checksum audit passed.
  • Cold-index cost passed without changing its baseline after statement-level attribution and SQL optimization.
  • Tier-3 scale passed on Django and rust-analyzer (890445 references, six positive controls); both are below the separate one-million-edge daemon cap.
  • Both plugin payload benchmarks passed: 12472/13058 tokens, all 20 expected items correct across 19 questions; the +555-token change is attributed to snapshot/freshness evidence and cursor hints.
  • Package baseline changed only for schema conditions, with zero projection changes.

Refs #245, #246, #250, #251, #253, #260, #261, #262.

Queries could combine different SQLite snapshots while reporting only Git provenance, and negative answers did not disclose working-tree changes beyond indexed content. This change adds transactional content identities, evidence from the snapshots actually read, RPC propagation, content-bound cursors, compound-query consistency checks, and bounded freshness observations. Python imports resolve by proven module and export origin, including aliases, relative imports and conservative re-exports. Ambiguous or shadowed origins remain unresolved. Schema 67 repairs existing Python bindings; actual Flask and Django v65 databases upgrade to the same bindings as fresh indexes. The untyped storage.request.COOKIES chain in #250 remains outside proven type flow. Executable build identities are unified, archive member versions and installer staging are verified, and routing timing assertions use deterministic work counts. Windows smoke stages the four release binaries in a fresh directory; unexpected executables within an archive are still rejected. ### Corpus effects All nine pinned repositories were compared against clean master 017c6d8 using occurrence-aware joins and source adjudication. Reference populations are unchanged; all seven non-Python repositories are bind-for-bind unchanged. | Corpus | Correct gains | False bindings removed | Correct losses | Conditionally correct losses | Corrected targets | |---|---:|---:|---:|---:|---:| | Django | 1715 | 1126 | 74 | 76 | 2 | | Flask | 13 | 10 | 2 | 0 | 0 | Correct losses include composed exports, extra import roots and object/ancestry flows not modeled here. Conditional losses involve runtime proxies, GIS configuration and task decorators. These accepted coverage losses are recorded alongside the gains. Historical #247 residuals remain tracked in #263; no rerun of that historical census is claimed. The approved structural, resolver-stage and tier-3 records were generated by the existing measurement writers, with generation identities, categorized diffs and positive controls. Flask resolves one additional reference overall; Django resolves 439 more. The structural exception and complete target-movement review are documented in the records. ### Measurement records Corpus response budgets record snapshot evidence costs of +816/+912/+840 tokens for C#/Flask/Rust and freshness costs of +71/+0/+70. Attribution preserves the previous history and separates inherited record drift from these exact field costs. Questions, calls, answer quality, fallback counts and competitor populations are unchanged. The new recorded totals are 10645/10311/9976; fresh verification measured 10651/10304/9970. Ruby package cost was measured in isolation under schema 67 / package 0.6.0: vm_step 26439909, fullscan_step 584758, sort 297, autoindex 20745, wall ratio 135%. These remain inside the previous bands. A subsequent verification also passed. All tolerance multipliers, the 60-token response drift allowance, reserve policy and existing plugin benchmark records are unchanged. ### Validation - On 296cc58, native Windows CI passed workspace tests, all eight staged shipped-set smoke checks and all six release-worker smoke checks. Linux CI passed fmt, clippy, MSRV, windows-gnu, ABI32/wasm, deny, private-item docs, complete workspace and full daemon transport. - On 022d665, release structural/stage/tier-3/Ruby gates passed: 26 tests. Real-corpus benchmarks and attribution checks passed: 7 tests. Formatting and diff checks passed. Full PR CI passed on 022d665: native Windows (including staged shipped-set smoke 8/8 and release-worker smoke 6/6), complete Linux workspace, full daemon transport, corpus, formatting, lint, compatibility, dependencies and documentation. Corpus CI measured 10654/10312/9970 response tokens, inside the unchanged tolerances. - Complete earlier local workspace: 3762 passed, 43 ignored, 347 test groups. Full daemon-backed MCP suite passed. - Release precision gate passed 7/7 against its declared synthetic decoys; it covers zero corpus repositories. - 32 mutation checks killed their intended tests; source restoration was verified by checksum. - Linux release archive smoke passed 8/8; installer source/checksum audit passed. - Cold-index cost passed without changing its baseline after statement-level attribution and SQL optimization. - Tier-3 scale passed on Django and rust-analyzer (890445 references, six positive controls); both are below the separate one-million-edge daemon cap. - Both plugin payload benchmarks passed: 12472/13058 tokens, all 20 expected items correct across 19 questions; the +555-token change is attributed to snapshot/freshness evidence and cursor hints. - Package baseline changed only for schema conditions, with zero projection changes. Refs #245, #246, #250, #251, #253, #260, #261, #262.
fix: bind query evidence and Python imports to proven index state
Some checks failed
CI / cargo fmt (pull_request) Successful in 51s
CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
CI / cargo doc (intra-doc links) (pull_request) Successful in 5m46s
CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 5m47s
CI / cargo check (MSRV 1.98) (pull_request) Successful in 5m54s
CI / cargo clippy (pull_request) Successful in 5m58s
CI / cargo check (windows-gnu) (pull_request) Successful in 6m19s
CI / cargo deny (pull_request) Successful in 6m27s
CI / OSS corpus (tier 1) (pull_request) Failing after 25m28s
CI / cargo test (pull_request) Successful in 24m34s
CI / cargo test (daemon transport) (pull_request) Successful in 13m27s
CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Failing after 45m39s
a2a2b3f8bd
Add transactional content identities and query-scoped SQLite snapshot evidence,
propagate it over RPC, bind cursors to content, and disclose bounded freshness
for negative answers. Resolve Python imports by exact module/export origin and
repair existing databases on upgrade.

Unify executable build identities, verify release archive versions and installer
staging, and replace routing timing assertions with deterministic work counts.

Local workspace, daemon MCP, docs, precision, cost and release smoke checks pass.
The protected corpus baseline remains unchanged: its Flask structural gate is
red and requires an explicit reviewed exception before merge.

Refs: #245, #246, #250, #251, #253, #260, #261, #262
ci: stage shipped Windows binaries before version smoke
Some checks failed
CI / cargo fmt (pull_request) Successful in 53s
CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
CI / cargo doc (intra-doc links) (pull_request) Successful in 7m9s
CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 7m23s
CI / cargo check (MSRV 1.98) (pull_request) Successful in 8m0s
CI / cargo deny (pull_request) Successful in 8m4s
CI / cargo clippy (pull_request) Successful in 8m15s
CI / cargo check (windows-gnu) (pull_request) Successful in 8m29s
CI / OSS corpus (tier 1) (pull_request) Failing after 40m17s
CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 51m24s
CI / cargo test (pull_request) Successful in 43m54s
CI / cargo test (daemon transport) (pull_request) Successful in 13m56s
CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
296cc583a4
The build directory also contains helper executables left by tests. Copy the
four release binaries into a fresh directory before the shipped-set smoke, so
version discovery grades the archive population. Keep executable enumeration
strict so an unexpected executable in a staged archive still fails.

Validated the workflow scope guard and a real-process Linux reproduction:
dirty build directory rejected, clean staged set 8/8, contaminated archive
rejected. Native Windows CI will validate the PowerShell staging path.

Refs: #262, #264
Record reviewed corpus and query-evidence measurements
All checks were successful
CI / cargo fmt (pull_request) Successful in 50s
CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
CI / cargo doc (intra-doc links) (pull_request) Successful in 4m53s
CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 5m17s
CI / cargo clippy (pull_request) Successful in 5m18s
CI / cargo check (MSRV 1.98) (pull_request) Successful in 5m40s
CI / cargo deny (pull_request) Successful in 5m58s
CI / cargo check (windows-gnu) (pull_request) Successful in 6m9s
CI / OSS corpus (tier 1) (pull_request) Successful in 25m7s
CI / cargo test (pull_request) Successful in 24m39s
CI / cargo test (daemon transport) (pull_request) Successful in 7m57s
CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 50m15s
022d6653d0
Apply the approved five-record proposal with source-adjudicated Python coverage tradeoffs, measured snapshot and freshness token costs, and schema-67 Ruby cost conditions. Preserve tolerance multipliers, corpus populations, plugin benchmarks, and prior attribution history.
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
h-dv/code-index!264
No description provided.