docs: record P6 implementation, contract, and automated acceptance PASS

This commit is contained in:
2026-08-13 12:44:19 +02:00
parent 124891bbfe
commit be0e68e77d
3 changed files with 82 additions and 12 deletions
@@ -79,6 +79,23 @@ thothctl --installation <absolute>/thothii-installation.yaml workspace vector re
- `preprocess run` continues only with the exact accepted blob digest and a compatible reusable
DWH binding; otherwise it records a new review checkpoint.
## Commit-addressed Evidence materialization (P6)
- Filesystem Evidence `<workspace-id>/evidence` is materialized from the exact pinned Git commit
into the immutable revision content root `<registry>/snapshots/<commit>/<id>/evidence` at
activation, with a sibling bounded manifest `<id>/evidence.manifest.json` whose digest is chained
into `snapshot.json`.
- Materialization uses fixed Git plumbing (`ls-tree -r -z` + `cat-file blob`) and refuses symlinks
and gitlinks at any depth, traversal/absolute/duplicate/cross-namespace paths, and non-regular
modes. Installation-local limits bound entry count (default 4096), total bytes (64 MiB),
per-file bytes (8 MiB), path bytes (4096), and manifest bytes (1 MiB); a size-sum preflight runs
before any bytes are written and no partial root is published.
- `preprocess evidence` and `preprocess run` operate directly on the materialized root; the
temporary `evidence_materialization_required` stop is retired (the code remains only for
pre-P6 compatibility). HTTP/S3 Evidence is unchanged.
- Materialized roots are retained with their commit-addressed snapshot directory and removed only
when the revision becomes unreferenced.
## Validation
- `--installation` is mandatory and absolute.
@@ -133,6 +150,9 @@ The request is streamed as one schema-versioned JSON document over stdin. Public
`thothctl --json` parses the operator stdout strictly and re-encodes only the public fields above.
`evidence_materialization_required` is retained for pre-P6 compatibility; since P6, filesystem
Evidence is materialized at activation and preprocesses directly.
## Exit codes
- `0`: `succeeded`, `unchanged`, or `dry_run`
+29 -11
View File
@@ -164,25 +164,43 @@ Checks:
Decision: **PASS** (owner approval 2026-08-13).
## P6 — Commit-addressed Evidence materialization
**Status:** instructions to be finalized by P6 implementation; not yet runnable.
**Status:** P6 implementation complete; automated integration PASS; manual acceptance PENDING.
Manual goal: materialize filesystem Evidence from the pinned Git commit, inspect its bounded
manifest, preprocess/index it, retrieve only the pinned revision, and exercise unsafe-tree and
aggregate-limit failures without partial publication.
Checks to fill during P6:
Commands (contract: `docs/contracts/workspace-preprocessing-cli.md`):
1. exact commit/tree/object identities;
2. successful atomic materialization;
3. manifest and file digest verification;
4. filesystem Evidence dry-run/run/idempotency;
5. revision-filtered Qdrant retrieval and corpus ACTIVE;
6. nested symlink/gitlink/traversal/special-file refusal;
7. file-count/total-byte/path/manifest limit refusal;
8. retention while pinned and owned cleanup after release.
```bash
thothctl --installation <abs>/thothii-installation.yaml workspace inspect --workspace <id> --json
thothctl --installation <abs>/thothii-installation.yaml workspace preprocess evidence --workspace <id> --dry-run --json
thothctl --installation <abs>/thothii-installation.yaml workspace preprocess evidence --workspace <id> --json
thothctl --installation <abs>/thothii-installation.yaml workspace preprocess evidence --workspace <id> --json # idempotent rerun
```
Checks:
1. exact commit/tree/object identities: after activation the materialized root is
`<registry>/snapshots/<commit>/<id>/evidence` and its sibling manifest
`<id>/evidence.manifest.json` records `workspace`, `commit`, `tree`, per-file `oid`/`digest`,
`entryCount`, `totalBytes`; `snapshot.json` chains the manifest digest;
2. successful atomic materialization: every regular blob is present byte-for-byte; the manifest
digests match;
3. manifest and file digest verification: re-activation reuses a valid root and fails closed on a
tampered manifest;
4. filesystem Evidence dry-run/run/idempotency: `--dry-run` returns `dry_run`, the real run
publishes, rerun is `unchanged`;
5. revision-filtered Qdrant retrieval and corpus ACTIVE: Evidence records carry the pinned
`workspace_revision`;
6. nested symlink/gitlink/traversal/special-file refusal: a commit introducing one of these fails
activation (`workspace_invalid`) and the previous valid revision stays active;
7. file-count/total-byte/path/manifest limit refusal: an oversized or over-count tree fails closed
without a partial publication;
8. retention while pinned and owned cleanup after release: the materialized root persists for a
pinned revision and is removed with its snapshot directory once unreferenced.
Decision: **PENDING**.
## Final aggregate P2–P6 verification
**Status:** runnable only after P6.