docs(canon): accept ADR-012 and retract the parts it supersedes
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

ADR-012 accepted 2026-08-25.

ADR-010 — partially superseded, notes added inline:
  decision 1: "a reading of the repositories" never said which copy, and the
    answer was neither the forge nor a working copy but whichever checkout last
    synced. The hub holds no repository files and never reads one.
  decision 5: "central derives, does not accept pushes" was policy while the
    workstation pushed everything.
  decision 6: "preliminary" was named but never built.

ADR-003 — partially superseded:
  decision 2: fingerprints composed from filesystem mtime are invalidated in
    part. mtime is a property of one workstation, differs across clones, and
    says nothing about content. Evidence: git_fingerprint for the-custodian
    held the initial commit while last_state_synced_at was minutes old.
  decision 5: the rebuild principle was correct but never exercised, and its
    "without data loss" claim holds only while nothing exists solely in the hub
    — which was false for 111 records on 2026-08-25.

ADR-001, ADR-005, ADR-007 and ADR-011 reviewed and unaffected; ADR-007 is
reinforced, since derived identifiers let an overlay and a forge-derived
projection compute the same identity.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-25 21:44:14 +02:00
parent 8c2825f4c3
commit c0cead2169
3 changed files with 59 additions and 5 deletions

View file

@ -16,7 +16,9 @@ tags: ["architecture", "state-hub", "repo-manager", "hub-core", "authority", "ca
## Status
Proposed.
Proposed, and **partially superseded by `ADR-012`** (accepted 2026-08-25).
Decisions 1, 5 and 6 are sharpened or given a mechanism there; see the notes on
each below. Everything else in this ADR remains in force.
## Context
@ -69,6 +71,12 @@ Hub — running on railiance — is authoritative. It is authoritative *as a rea
of the repositories*, not as a second place data lives. Repository files remain
the source of truth (`ADR-001`).
> **Sharpened 2026-08-25 by `ADR-012` decision 1.** "A reading of the
> repositories" never said *which* copy of them, and the honest answer was
> neither the forge nor any particular working copy: the projection derived from
> whichever checkout last ran the sync. The hub holds no repository files at all
> and never reads one. `ADR-012` names the forge as the projection source.
**2. A local hub is a cache, never a database.** Local instances hold a
rebuildable projection. A cache may be discarded and reconstructed from the
repositories at any time, and losing it must never lose work.
@ -118,11 +126,23 @@ conflict and belongs to git.
"Authoritative" means authoritative *reading*, so nothing may inject derived
state directly. Hub-native records are the exception and keep a real write path.
> **Sharpened 2026-08-25 by `ADR-012` decision 6.** This was policy, not
> practice: nothing derived, and the workstation pushed everything. `ADR-012`
> retires push-based sync as the primary path so that "central derives" becomes
> true rather than aspirational.
**6. Preliminary until confirmed.** Locally registered data and uncommitted
repository state are preliminary until the central service has seen them.
Mitigation is by changing the repository files and the local cache — never by
editing central to match a local view.
> **Given a mechanism 2026-08-25 by `ADR-012` decisions 3 and 4.** "Preliminary"
> was named here but never built, so in practice locally registered data was
> indistinguishable from derived state once it arrived. It is now a labelled
> overlay within the same projection — explicitly not a second store — and it
> retires when the commit carrying it reaches the forge. The prohibition on
> editing central to match a local view is unchanged.
Combined with `ADR-007` decision 2 (identifiers derived from `PREFIX-WP-NNNN`),
"preliminary" largely stops mattering: a cache computes the same identifier
central will, so offline-registered data is already correct on arrival and needs