From a4637fdaf3e219c6fe0aa1332df97e4c9808a744 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 17 Aug 2026 13:04:03 +0200 Subject: [PATCH] docs: renumber ADR-008 -> ADR-010 after canon ID collision ADR-008 was concurrently allocated by two authors on 2026-08-17: the multi-tenancy framework (earlier provenance, draft-1 lineage) and the hub authority model. The multi-tenancy ADR keeps 008; the hub authority model becomes ADR-010. Also corrects the 'read replica' phrasing in T01, superseded by ADR-010. Co-Authored-By: Claude Opus 5 --- ...0005-registrar-consolidation-deterministic-ids.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md index 3aa9544..68ecf1a 100644 --- a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md +++ b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md @@ -55,7 +55,7 @@ priority: high Until derivation ships, exactly one instance may write hub identifiers into repository files. The interim registrar is the automated production instance; -workstation hubs are development read replicas. +workstation hubs are rebuildable caches (`ADR-010` decision 2). - Make the writeback path refuse to mint identifiers when the instance is not the registrar, rather than relying on operator discipline. @@ -152,14 +152,14 @@ status: wait priority: high ``` -Implement `ADR-008` decisions 1–3: the central hub on railiance is authoritative +Implement `ADR-010` decisions 1–3: the central hub on railiance is authoritative as a *reading* of the repositories; local instances become rebuildable caches. - A cache must be discardable and reconstructable from repository files alone, with no work lost. - Local work must not require a hub — repository files are self-describing, so reading them is sufficient for working inside a repo. -- Cache reads are advisory and must carry their staleness (`ADR-008` decision 8). +- Cache reads are advisory and must carry their staleness (`ADR-010` decision 8). Measured 2026-08-17: 955 workplans locally against 649 on the primary, 320 local-only, of which **288 are backed by files that all exist on disk**. That @@ -173,7 +173,7 @@ status: wait priority: high ``` -Implement `ADR-008` decision 4. The two kinds need opposite handling: +Implement `ADR-010` decision 4. The two kinds need opposite handling: - **File-derived** (workplans, tasks, statuses, dependencies) — central derives it and must not accept pushes of it (decision 5). Offline, the git commit *is* @@ -201,7 +201,7 @@ priority: high 28 records exist in the local instance with no backing file. They are the only records a cache rebuild would drop, so they must be classified first -(`ADR-008` § Orphan disposition): +(`ADR-010` § Orphan disposition): 1. **Broken links** — a file exists but `backing_filename` was never recorded. `RMGR-WP-0004` is a confirmed instance. Repair the link; no data at risk. @@ -229,7 +229,7 @@ status: wait priority: medium ``` -Implement `ADR-008` decision 7. The retirement splits one hub into several, which +Implement `ADR-010` decision 7. The retirement splits one hub into several, which is permitted only if every record has exactly one authoritative hub, determined by its repository and domain.