docs: design P2-P6 workspace preprocessing

This commit is contained in:
2026-08-10 18:59:31 +02:00
parent 2e95101aa3
commit 16ee92c8f9
2 changed files with 399 additions and 0 deletions
+128
View File
@@ -0,0 +1,128 @@
# P2–P6 Manual Verification Walkthrough
> Living document. Each section is completed with exact released commands and artifacts during its
> corresponding plan. Automated integration and manual acceptance use separate clean state.
## Global rules
- Use a new temporary operator root and a new private fixture Git remote for each Px.
- Never use production PSD credentials in a retained report or screenshot.
- Keep descriptor/content in Git; keep endpoints, bindings, credentials, and certificates in the
installation-local protected directory.
- Do not print secret files, rendered signed URLs, Compose environments, or unbounded logs.
- Record the ThothII commit, workspace commit, installation descriptor path, Compose project name,
command exit status, and report path.
- A focused manual PASS does not replace the automated process goal.
## P2 — Host preprocessing CLI
**Status:** instructions to be finalized by P2 implementation; not yet runnable.
Manual goal: from a clean local installation, use only `thothctl` on the host to inspect one
registry workspace and execute the controlled REST-DWH/HTTP-Evidence preprocessing path without a
host Python or Node runtime.
Checks to fill during P2:
1. installation/render preflight;
2. workspace inspection and exact revision display;
3. DWH preprocessing and resume;
4. FK machine output and manual-review checkpoint;
5. schema check/index;
6. HTTP Evidence dry-run and real run;
7. idempotent rerun;
8. filesystem Evidence stable deferred error;
9. secret scan and exact cleanup.
Decision: **PENDING**.
## P3 — Effective config and `.tht-dwh`
**Status:** instructions to be finalized by P3 implementation; not yet runnable.
Manual goal: compare operator and session effective DWH identities, inspect `OWNER.json` and
`ACTIVE` without exposing secrets, prove safe reuse after a content-only revision, and prove
fail-closed behavior after a DWH-affecting change.
Checks to fill during P3:
1. canonical fingerprint comparison;
2. stable logical config-source identity;
3. schema-v1 ownership compatibility/migration;
4. DWH cache reuse across equivalent revisions;
5. revision-scoped schema/Evidence state;
6. mismatch rejection and recovery.
Decision: **PENDING**.
## P4 — Qdrant bootstrap and guarded rebuild
**Status:** instructions to be finalized by P4 implementation; not yet runnable.
Manual goal: prove admission creates a missing compatible collection and indexes, refuses an
incompatible collection, and permits destructive rebuild only under durable maintenance with no
active readers/jobs and exact repeated confirmation.
Checks to fill during P4:
1. missing-collection self-heal;
2. missing-index self-heal;
3. dimensions/distance/index-type refusal;
4. confirmation mismatch refusal;
5. active-reader/job refusal;
6. successful drained rebuild;
7. interrupted rebuild recovery with maintenance retained.
Decision: **PENDING**.
## P5 — Curated FK annotations in Git
**Status:** instructions to be finalized by P5 implementation; not yet runnable.
Manual goal: curate `workspace-content/<id>/schema/annotations.yaml` in an author clone, publish it,
pull the new revision, explicitly accept the reviewed blob, and prove atomic revision-correct sync
without changing `physical.yaml` in Git.
Checks to fill during P5:
1. candidate/export review;
2. Git commit and exact blob identity;
3. pull and controlled revision transition;
4. explicit acceptance record;
5. synchronized destination and ownership manifest;
6. malformed/oversized/symlink/cross-namespace refusal;
7. pinned historical revision isolation.
Decision: **PENDING**.
## P6 — Commit-addressed Evidence materialization
**Status:** instructions to be finalized by P6 implementation; not yet runnable.
Manual goal: materialize filesystem Evidence from the pinned Git commit, inspect its bounded
manifest, preprocess/index it, retrieve only the pinned revision, and exercise unsafe-tree and
aggregate-limit failures without partial publication.
Checks to fill during P6:
1. exact commit/tree/object identities;
2. successful atomic materialization;
3. manifest and file digest verification;
4. filesystem Evidence dry-run/run/idempotency;
5. revision-filtered Qdrant retrieval and corpus ACTIVE;
6. nested symlink/gitlink/traversal/special-file refusal;
7. file-count/total-byte/path/manifest limit refusal;
8. retention while pinned and owned cleanup after release.
Decision: **PENDING**.
## Final aggregate P2–P6 verification
**Status:** runnable only after P6.
The final manual pass will start with a new registry and two independent installations. It will
run the complete DWH → FK → schema → filesystem Evidence chain, prove idempotency and revision
isolation, confirm the second installation uses its own secrets/state, and compare its observations
to the retained aggregate automated report.
Decision: **PENDING**.