Verified blocker of #901
The admitted final-source S20 run at 9312a47096d16af66313fee2aeeb766c892b906d passes its complete lifecycle and records construction chunks, accepted rows, artifact/sync counts, phase I/O, RSS and allocated owners. However, s20-graphforge.json contains only whole-ingest duration (228,159 ms), not the separate append/seal/recovery durations explicitly required by #901.
ImportConstructionEvidence has no phase duration fields. ImportProgress.elapsed_millis is cumulative checkpoint time and is not a substitute. The CLI also omits that field; the certifier cannot recover missing durations. The Rust test client has its own timers, but it is not the executed ordinary CLI host path. This is one verified evidence cause, not a new construction optimization or certification tracker.
Bounded repair
Keep canonical #901 as the close gate. Add per-public-operation, non-durable timing observations to the existing GraphImportSession → CLI receipt → certifier path. Measure disjoint construction begin/resume, append calls, validate/seal and publication calls. Distinguish fresh construction from resumed authentication. Include call counts, reset for each public operation, and record elapsed time before propagating returned errors. No manifests, storage format, compatibility machinery, generic telemetry framework or new workflow.
Append-call timing excludes source decode/normalization/checkpoint work outside those calls; its sum is not whole-ingest time. Successful command receipts may be summed across validate/commit, but lost-process work is unobserved and must never be reconstructed. Timings are observations, not noisy performance CI thresholds.
Acceptance
Native child and blocker of #901, limited to its existing elapsed-time criterion. #901 will own the post-merge existing S20/S22 integrated receipts and final acceptance ledger. Let the current safe S22 run finish and retain it honestly. Do not start S24/S26 or a new certification workflow.
Implemented validation
Reader prerequisite #1257 is merged as ee51135d82fc8fb78c66eeebc0de6153a525c7c8. The timing repair at 89eac8ee05277a3da64776313d99465c8738d0e5 preserves the original immediate relationship-count assertion and passes it. Full API 739 passed; direct API/CLI timing regressions passed; certifier 28 passed; schema smoke 8 passed; public surface policy 12 passed; registry 14 passed. Workspace/certifier Clippy and fast checks passed. Full local pre-push stopped only at existing #1192 (storage 1,097 passed, 1 failed, 2 existing ignored); later local stages were not reached.
The existing tiny lifecycle ran with frozen, hash-verified CLI/certifier/generator and passed all 10 phases. Actual sanitized validation receipts contain begin1/append2/seal1; the separate commit process contains resume1/publish1, all errors0. Executable hashes remained unchanged. This verifies receipt propagation, not a performance improvement. Final exact-head PR CI and merge remain pending; #901 still owns the fresh merged-source S20/S22 ledger.
Verified merged outcome
PR #1259 squash merged as 24ca688c516a86a68de9cffaab2d5a9215291256 at 2026-09-11T12:43:53Z; issue closure verified at 12:43:55Z. Exact PR head 3af0f323e33999185d54e518cd3d9678f553158c passed CI run 34598854650 and CI Gate; merge state CLEAN, no unresolved threads, closing reference exactly #1256. The initial CI run exposed one parity-inventory cause across policy/Python/Node; explicit Rust/CLI diagnostic classification and frozen inventory updates passed final CI. The full frozen tiny proof above predates only those policy/documentation changes. Final merged-source S20/S22 remains with #901.
Verified blocker of #901
The admitted final-source S20 run at
9312a47096d16af66313fee2aeeb766c892b906dpasses its complete lifecycle and records construction chunks, accepted rows, artifact/sync counts, phase I/O, RSS and allocated owners. However,s20-graphforge.jsoncontains only whole-ingest duration (228,159 ms), not the separate append/seal/recovery durations explicitly required by #901.ImportConstructionEvidencehas no phase duration fields.ImportProgress.elapsed_millisis cumulative checkpoint time and is not a substitute. The CLI also omits that field; the certifier cannot recover missing durations. The Rust test client has its own timers, but it is not the executed ordinary CLI host path. This is one verified evidence cause, not a new construction optimization or certification tracker.Bounded repair
Keep canonical #901 as the close gate. Add per-public-operation, non-durable timing observations to the existing
GraphImportSession→ CLI receipt → certifier path. Measure disjoint construction begin/resume, append calls, validate/seal and publication calls. Distinguish fresh construction from resumed authentication. Include call counts, reset for each public operation, and record elapsed time before propagating returned errors. No manifests, storage format, compatibility machinery, generic telemetry framework or new workflow.Append-call timing excludes source decode/normalization/checkpoint work outside those calls; its sum is not whole-ingest time. Successful command receipts may be summed across validate/commit, but lost-process work is unobserved and must never be reconstructed. Timings are observations, not noisy performance CI thresholds.
Acceptance
Native child and blocker of #901, limited to its existing elapsed-time criterion. #901 will own the post-merge existing S20/S22 integrated receipts and final acceptance ledger. Let the current safe S22 run finish and retain it honestly. Do not start S24/S26 or a new certification workflow.
Implemented validation
Reader prerequisite #1257 is merged as
ee51135d82fc8fb78c66eeebc0de6153a525c7c8. The timing repair at89eac8ee05277a3da64776313d99465c8738d0e5preserves the original immediate relationship-count assertion and passes it. Full API 739 passed; direct API/CLI timing regressions passed; certifier 28 passed; schema smoke 8 passed; public surface policy 12 passed; registry 14 passed. Workspace/certifier Clippy and fast checks passed. Full local pre-push stopped only at existing #1192 (storage 1,097 passed, 1 failed, 2 existing ignored); later local stages were not reached.The existing tiny lifecycle ran with frozen, hash-verified CLI/certifier/generator and passed all 10 phases. Actual sanitized validation receipts contain begin1/append2/seal1; the separate commit process contains resume1/publish1, all errors0. Executable hashes remained unchanged. This verifies receipt propagation, not a performance improvement. Final exact-head PR CI and merge remain pending; #901 still owns the fresh merged-source S20/S22 ledger.
Verified merged outcome
PR #1259 squash merged as
24ca688c516a86a68de9cffaab2d5a9215291256at 2026-09-11T12:43:53Z; issue closure verified at 12:43:55Z. Exact PR head3af0f323e33999185d54e518cd3d9678f553158cpassed CI run 34598854650 and CI Gate; merge state CLEAN, no unresolved threads, closing reference exactly #1256. The initial CI run exposed one parity-inventory cause across policy/Python/Node; explicit Rust/CLI diagnostic classification and frozen inventory updates passed final CI. The full frozen tiny proof above predates only those policy/documentation changes. Final merged-source S20/S22 remains with #901.