docs: specify THOTH-DB-CTRL-01 Diesel generation control - #775
Conversation
Immutable exact-head evidence — THOTH-DB-CTRL-01-SPECThis top-level evidence comment is immutable. If correction is required, a separate superseding comment must be posted; this comment will not be edited. Exact repository state
Ordered commits:
Exact paths:
Local investigation commands and concise resultsTool versions: Exact isolated CLI install: cargo install diesel_cli \
--version '2.3.10' \
--root /private/tmp/thoth-db-ctrl-diesel-cli-2.3.10 \
--no-default-features \
--features postgres \
--lockedResult: exit 0; exact PostgreSQL-only CLI Migration commands from repository root, with the disposable URL supplied through the task-local environment variable: cargo run migrate --database-url "$THOTH_DB_CTRL_DATABASE_URL"
cargo run migrate --revert --database-url "$THOTH_DB_CTRL_DATABASE_URL"
cargo run migrate --database-url "$THOTH_DB_CTRL_DATABASE_URL"Results: Current config parse command: /private/tmp/thoth-db-ctrl-diesel-cli-2.3.10/bin/diesel \
print-schema \
--database-url "$THOTH_DB_CTRL_DATABASE_URL" \
--config-file /Users/ja573/thoth/diesel.tomlResult: non-zero: A valid copied config with Baseline generation commands used exact CLI /private/tmp/thoth-db-ctrl-diesel-cli-2.3.10/bin/diesel \
print-schema \
--database-url "$THOTH_DB_CTRL_DATABASE_URL" \
--config-file "$THOTH_DB_CTRL_MINIMAL_CONFIG" \
> /private/tmp/thoth-db-ctrl-01-spec-artifacts/schema-2.3.10-first.rs
/private/tmp/thoth-db-ctrl-diesel-cli-2.3.10/bin/diesel \
print-schema \
--database-url "$THOTH_DB_CTRL_DATABASE_URL" \
--config-file "$THOTH_DB_CTRL_MINIMAL_CONFIG" \
> /private/tmp/thoth-db-ctrl-01-spec-artifacts/schema-2.3.10-second.rsResults: Differences were fully classified: config/path error; CLI-version sensitivity; formatting and macro qualification; invalid custom-type derive configuration; and maintained canonical conventions ( A full raw-to-canonical patch recreated the baseline but failed at hunk 16 after controlled disposable cargo check -p thoth-api --features backendreturned exit 101 with 86 errors: missing supplemental Disposable target and cleanup proofThe credential and full URL are intentionally omitted. The container had Selected approach and rejected alternativesSelected: retain root Rejected:
Complete-range validationComplete five-path classifier: {"docs_only":"true","run_build":"false","run_docker":"false","run_migrations":"false"}Exact-head pull-request CIEvery run is
All required skipped job step arrays are absent ( State and effect assessmentNo evidence-only third commit will be created. Fresh independent cross-model review is mandatory. Fresh explicit CTO authorization is required before this specification PR may be marked ready or merged. Merging this specification will not authorize |
Superseding immutable exact-head evidence — THOTH-DB-CTRL-01-SPECThis comment supersedes the original immutable evidence comment at #775 (comment) for the new exact head. The original comment was not edited. Exact repository and pull-request state
Ordered commits:
Exact cumulative paths:
The remediation commit changes only the implementation report and task specification. P1 correctionThe review of The corrected contract now requires:
The implementation report now states exactly what discovery proved: No claim is made that Complete-range local validationComplete five-path classifier: {"docs_only":"true","run_build":"false","run_docker":"false","run_migrations":"false"}Exact-head pull-request CIEvery run is
No workflow was manually dispatched. State and effect assessmentThe PR body is updated for this exact head. The PR remains draft. This remediation does not supply independent approval or CTO authorization. Required next gates:
Do not mark PR #775 ready or merge it on this evidence alone. |
Superseding immutable exact-head evidence — THOTH-DB-CTRL-01-SPECThis comment supersedes the prior exact-head evidence at #775 (comment) for the new head. Neither earlier immutable evidence comment was edited. Exact repository and pull-request state
Ordered commits:
Exact cumulative paths:
The latest remediation commit changes only the implementation report and task specification. P1 correction: compile-valid controlled probeThe review of The historical publisher-column experiment remains truthful rejection evidence for the raw and patch approaches. It is no longer the future compile-success acceptance probe. The corrected future probe creates only: CREATE TABLE public.thoth_db_ctrl_probe (
probe_id uuid PRIMARY KEY,
probe_value text
);Its expected manifest is exactly: version = 1
add = [
"allow-table:public.thoth_db_ctrl_probe",
"column:public.thoth_db_ctrl_probe.probe_id",
"column:public.thoth_db_ctrl_probe.probe_value",
"primary-key:public.thoth_db_ctrl_probe",
"table:public.thoth_db_ctrl_probe",
]
remove = []
change = []The grammar now includes Required acceptance sequence:
Focused compile validationThe repository claim was checked directly:
A detached temporary worktree at cargo check -q -p thoth-api --features backendResult: exit 0 with no output. No model fixture was added. The temporary schema candidate was not committed; the detached worktree and its build artifacts were removed. This proves the chosen schema-only candidate is compile-valid. The future synchronizer must still prove exact manifest equality, deterministic rendering, table removal, and byte-identical restoration. Complete-range local validationComplete five-path classifier: {"docs_only":"true","run_build":"false","run_docker":"false","run_migrations":"false"}Exact-head pull-request CIEvery run is
No workflow was manually dispatched. State and effect assessmentThe prior safe-target correction remains intact and was explicitly confirmed by the latest review. The PR body is updated for this exact head. The PR remains draft. This remediation does not supply independent approval or CTO authorization. Required next gates:
Do not mark PR #775 ready or merge it on this evidence alone. |
|
Reviewed exact head: Against exact base: PR #775 is open, draft, mergeable and unmerged, with four commits and five cumulative changed paths. Independence attestation: this was a fresh, read-only review. I did not modify repository files, commits, branches, PR metadata, comments, reviews, threads, checks or operational state. FindingsStandalone acceptance probeThe previous compile-validity P1 is fully resolved. The controlled acceptance probe is now a standalone disposable table: CREATE TABLE public.thoth_db_ctrl_probe (
probe_id uuid PRIMARY KEY,
probe_value text
);Its expected manifest explicitly contains exactly five independently checked structural effects: The specification requires exact manifest equality and prohibits the table, its columns, primary key or The required success contract is now internally consistent:
The acceptance criteria and test plan consistently require the same five-entry delta, no join, successful backend compilation, deterministic repetition, removal and clean restoration. Compile evidenceThe implementation report records a detached-worktree validation using only the equivalent standalone Diesel table block and allow-table membership: cargo check -q -p thoth-api --features backendThe recorded result was exit 0 with no output. The temporary candidate was not committed, and the worktree and build artifacts were removed. The report correctly limits this evidence: it proves that the chosen schema-only candidate is compile-valid, while the future implementation must still prove actual synchronizer output, manifest equality, deterministic generation, removal and baseline restoration. The underlying reasoning is sound: unlike the rejected publisher-column probe, the standalone table does not alter the row shape of an existing positional Safe-target contractThe earlier networking P1 remains correctly resolved. The specification:
No regression was introduced by the probe correction. Commit and scope boundariesThe corrected head is exactly one commit beyond: The fourth commit is: It changes exactly: The cumulative branch remains exactly four commits ahead of the unchanged base, with five paths and commit scopes: The ordered commits are: The cumulative paths remain: The superseding immutable evidence comment Live Review stateLive review queries returned: The specification remains draft and does not represent implementation approval. Exact-head CIAll four pull-request workflows completed successfully against exact head Every skipped job has an absent step array. Effects and control stateThe control records correctly retain: DecisionThis approval is bound exclusively to: It approves the It does not authorize:
Required next gates:
|
Programme and task
THOTH-DB-CTRL-01-SPECTHOTH-DB-CTRL-01develop@35e4dc20864ae4896dccc2b20cbcdbe3fb733db8a4db430cb3c80fc6c1fd4100821c643129e87d5fCommits and exact scope
bfee1ca8356ac191521e112f835bf3a4af0993d3—docs: specify THOTH-DB-CTRL-01 Diesel control— 4 paths3f0affd0e375975dd18ea895219ab77477b41325—docs: report THOTH-DB-CTRL-01 specification— 1 path9247cc5e4dbc82a5f4ecc381f8b8b5084c9bc628—docs: correct THOTH-DB-CTRL-01 target safety— 2 pathsa4db430cb3c80fc6c1fd4100821c643129e87d5f—docs: make THOTH-DB-CTRL-01 probe compile-valid— 2 pathsExact five paths:
CHANGELOG.mddocs/engineering/ai-delivery/tasks/THOTH-DB-CTRL-01.mddocs/engineering/ai-delivery/implementation-reports/THOTH-DB-CTRL-01-SPEC-implementation-report.mddocs/engineering/repository-map/control-gaps.mddocs/engineering/repository-map/repositories/thoth.mdReview remediations
Safe-target remediation
The exact-head review of
3f0affd0e375975dd18ea895219ab77477b41325returnedCHANGES REQUIREDwith one P1: the safe-target rule incorrectly required PostgreSQL's server-side accepted address to be loopback. The bounded remediation distinguishes the loopback client endpoint from server-side network evidence, requiresinet_server_addr(),inet_server_port(),inet_client_addr(), andinet_client_port()to be recorded and classified, and ties any accepted private bridge address to verified local Docker orrun_migrationsGitHub Actions provenance.Only the task specification and implementation report changed in the remediation commit. No discovery experiment was rerun, and no runtime, workflow, migration, schema, database, or production state changed.
Compile-valid probe remediation
The exact-head review of
9247cc5e4dbc82a5f4ecc381f8b8b5084c9bc628confirmed the safe-target correction and returned one new P1: the future schema-onlypublisher.thoth_db_ctrl_probecolumn would change the row shape loaded into the nine-field positionalPublishermodel and therefore could not satisfy the required focused compile-success gate.The future acceptance probe is now a standalone disposable table,
public.thoth_db_ctrl_probe(probe_id uuid PRIMARY KEY, probe_value text), with exactly five explicit manifest effects: table, two columns, primary key, andallow-tablemembership. It creates no join and has no consuming application model. The equivalent schema-only table and allow-table candidate passedcargo check -q -p thoth-api --features backendwith exit 0 and no output in a detached temporary worktree; that worktree and its artifacts were removed. The future synchronizer must still prove exact manifest equality, deterministic generation, table removal, and byte-identical baseline restoration.Only the task specification and implementation report changed in this remediation commit. No runtime, workflow, migration, production schema/database, deployment, release, or activation state changed.
Objective
Create the repository-authoritative, implementation-ready specification for a safe, repeatable Diesel migration and schema-generation procedure. This is documentation and discovery only; it does not implement the control.
Investigation findings
make migration,cargo run migrate --database-url "$DATABASE_URL", and disposable-onlycargo run migrate --revert --database-url "$DATABASE_URL".print_schema.filerelative to the configuration file. Rootfile = "src/schema.rs"therefore does not target canonicalthoth-api/src/schema.rs.diesel.tomlfails parsing because four commas are missing. A temporary commas-only repair still applies imports and model types as derives, so it is semantically invalid.2.3.10; isolated PostgreSQL-only CLI2.3.10generated 28,132-byte outputs twice with byte-identicalcmpresult.work_abstract/work_titlealiases, title identifier handling, supplementalMarkupFormat, maintainedTimestamptzmappings, model-compatible column order, or unchanged formatting.cargo check -p thoth-api --features backendwith 86 errors: missing supplemental type, alias/join mismatch, and pervasive DieselCompatibleTypeordering failures.Database safety evidence
A unique disposable
postgres:17container exposed its client endpoint only on127.0.0.1:55432, with databasethoth_ctrl_01_specand userthoth_ctrl. It had no host/repository mount and used one anonymous Docker volume. No production, staging, shared-development, or public database was contacted; no production credential was used.The discovery proved a loopback client endpoint and task-created disposable-container provenance. It did not record PostgreSQL's server-side accepted address or the server/client connection ports, so it does not claim that
inet_server_addr()was loopback. The corrected implementation specification requires those values to be queried and ties any private container-network address to verified Docker or GitHub Actions provenance.Migration results:
The container, both disposable databases, anonymous volume, detached worktree, generated artifacts, and isolated CLI were deleted. Container and volume lookups confirmed absence.
Selected implementation approach
Retain root
diesel.tomland canonicalthoth-api/src/schema.rs; correct the root-relative path and derive list; pin exact CLI2.3.10; add explicit convention control data; and add a fail-closed structural synchronizer that:run_migrationsGitHub Actions provenance;thoth-api/src/schema.rs;The exact future command contracts are defined in the specification. Clean check must be byte-identical and repeated generation deterministic. A controlled disposable probe must produce only its declared isolated diff, and removal must restore the clean baseline.
Rejected alternatives
Validation
git diff --check: exit 0, no output.4 / 1 / 2 / 2.{"docs_only":"true","run_build":"false","run_docker":"false","run_migrations":"false"}.Remaining gates and no-effect statement
THOTH-DB-CTRL-01implementation is not started or authorized. BE-01 remainsBLOCKED; no BE-01 or control implementation branch exists. CG-12 remains unresolved and closes only after the separate implementation passes acceptance evidence, independent review, and explicitly authorized merge. CG-13 remains open.This PR has no production migration, schema/data, runtime, API, deployment, release, or activation effect. Do not mark it ready, approve it, or merge it without fresh independent review and fresh explicit CTO authorization. Merging this specification will not authorize implementation.