Skip to content

fix(ops): prove the deployed archive is coherent after rebuild and repair #2308

Description

@Sinity

Outcome

The deployed Polylogue archive, daemon, CLI, browser-capture intake, and derived read models agree on one current state after the large rebuild/repair campaign. A restart does not regress authority, convergence, or queryability, and the operator can prove that with one bounded receipt set.

This is the public live closure gate, not a container for every historical deployment bug.

Current reality

Many original implementation gaps are already fixed: version probes, deployment smoke, browser-capture spool discovery/materialization, receiver lifecycle states, route availability, package closure, source-row-missing recovery, bounded health probing, replay/repair machinery, and substantial scale hardening.

The remaining question is empirical and whole-system:

Does the current deployed archive converge to a trustworthy fixed point, survive restart, and report the same truth through every operator surface?

Historical June measurements and one-off repairs remain evidence, but they are not current acceptance criteria unless reproduced on current code.

Required receipt set

Capture one coherent run containing:

  • expected and deployed commit/package identity;
  • source/index/user/ops/embedding schema identity;
  • raw-authority reconciliation result and unresolved conflicts/debt;
  • latest per-origin acquisition and index convergence;
  • browser-capture spool → raw → indexed identity/provenance;
  • bounded query/read smoke against the live archive;
  • daemon restart and post-restart convergence;
  • stale/interrupted attempt handling;
  • resource/time summary for startup, replay, derived rebuild, FTS finalization, and steady state;
  • explicit caveats for any deferred or intentionally unresolved debt.

Acceptance criteria

  • The canonical raw-authority reconciler reaches fixed point or emits a finite named set of unresolved conflicts requiring operator judgment.
  • Re-running the reconciliation is idempotent and does not replace accepted authority with a weaker/stale candidate.
  • Source, index, and derived materialization debt converge or remain explicitly bounded and explained.
  • A new browser capture is traced from receiver receipt through raw evidence to a nonzero-message indexed session with provenance identifying provider-native versus fallback capture where applicable.
  • polylogue, polylogued, daemon HTTP status/health, and deployment smoke agree on deployed version, archive root, schema state, browser-capture state, and current debt.
  • Stale running attempts are interrupted/recovered after process death; no phantom running work survives restart.
  • Restart followed by the same receipt set remains green without manual cursor edits, forged raw rows, or ad hoc SQL repair.
  • Representative live reads succeed under bounded resource/deadline controls; failures identify the exact stage and retained recovery state.
  • The final receipt names any remaining non-blocking debt and states why it does not invalidate archive trust.

Tracker authority

  • GitHub: public live closure outcome.
  • Bead implementation owner: polylogue-lkrc, one raw-authority reconciler (implements).
  • Bead executor: polylogue-hjpx, execute accepted replay plans to fixed point (implements).
  • Bead live gate: polylogue-yla8, operator-authorized replay/closure proof (implements).
  • Bead attestation slice: polylogue-s8q, deployed version/schema/origin attestation (implements, not a mirror of the whole issue).
  • Incident and repair Beads may close independently while this issue remains open until the aggregate receipt is coherent.

Non-goals

  • No fresh archive reset merely to obtain a green report.
  • No forged source rows or silent conflict resolution.
  • No reopening completed historical subproblems unless current evidence reproduces them.
  • No unbounded optimization campaign; performance work belongs here only when it blocks the live closure receipt or perf(archive): prove current full-corpus ingest and rebuild bounds #2391's current benchmark.
  • No closure based solely on unit tests or branch-local smoke.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:daemonDaemon and live service runtimearea:devtoolsDevtools and repo control-plane toolingarea:storageStoragetheme:operationsOperational health, backup, alerts, maintenancetheme:verifiabilitySchema-native proof and evidence architecturetype:fixBug fix

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions