Skip to content

fix(storage): separate UUID-membership and ordinal-identity authority manifests #974

Description

@DecisionNerd

Problem

The merged v4 ordinal reader reuses topology/uuid-membership/manifest.json, but the existing v3 manifest is the live UUID-membership authority for both nodes and edges. The v4 schema is node-only. Replacing v3 would break edge membership and existing consumers; treating a v3 body as v4 authority also conflates independent hashes and domains.

This is a verified blocker discovered while implementing #969. It corrects #970's reader contract without expanding construction scope.

Objective

Separate the existing UUID-membership facet from the node ordinal-identity facet while pinning both to the same topology generation.

Requirements

  • Preserve v3 topology/uuid-membership/manifest.json as node+edge UUID-membership and UUID-to-surrogate authority.
  • Place node ordinal v4 at a distinct canonical manifest/receipt/lock path.
  • Bind V4OrdinalIdentityAuthority.manifest_sha256 only to the authenticated ordinal manifest digest supplied by the selected project-generation receipt.
  • Separate ordinal-facet discovery/classification from authenticated open.
  • Valid current v3 with absent ordinal v4 returns a typed rebuild-required disposition.
  • Present malformed/corrupt ordinal v4 fails closed and never falls back to v3.
  • Keep existing v3 node+edge consumers unchanged.
  • Make orphan/reference discovery authenticate selected-generation receipt provenance and retain the union of both facets.
  • Document the two generation-coupled authority facets explicitly.

Acceptance Criteria

  • Distinct paths, hashes, receipts, and lock ownership are enforced.
  • Valid v3 plus absent v4 returns typed rebuild-required.
  • Malformed, substituted, or generation-mismatched v4 fails closed.
  • V3 node and edge membership remains exact and usable.
  • Cleanup never self-authorizes a manifest by hashing the file it is deciding to trust.
  • Reference/orphan inventory preserves all artifacts reachable from either facet.
  • Focused storage tests, formatting, clippy, Cargo/Bazel drift, and exact-head CI pass.

Non-Goals

Relationships

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions