Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 8 additions & 4 deletions .cursor/rules
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: c07a39007806f42609962111a70acbc6ddc3d591c058053a0ba5e01836c031df) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 9bd32aa128aca801628967581df3ff7e0b36a1137d517b708bab47b138fe8b6f) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

Expand Down Expand Up @@ -65,6 +65,7 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KVK19NPWFYC9** — ADR-074: The Graph Export Surfaces Typed Relationship Edges _(Technical)_
- **RAC-KVNM01QPBPXB** — ADR-075: The Pre-Merge Check Tier Is a Required Merge Gate on `main` _(Process)_
- **RAC-KVSQ2A0BB9XF** — ADR-079: Note-Tool Exports Are Ingested by Normalisation, Not markitdown _(Architecture)_
- **RAC-KVSTYDARXKYW** — ADR-080: The Single Source of Truth Is Git, Not a Database _(Architecture)_
- **RAC-KVTS86ZGVJV7** — ADR-077: The Two-Gate Capture Write Model _(Architecture)_
- **RAC-KW2YW6XK593X** — ADR-084: Read-Access Audit Recorder _(Product)_
- **RAC-KW47GFBHK31W** — ADR-086: Air-Gap Posture and Enterprise Telemetry Hard-Lock _(Product)_
Expand Down Expand Up @@ -98,17 +99,20 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-KZKMJ8Q49GHV** — ADR-133: Start Corpus Federation With One Direct Parent _(Architecture)_
- **RAC-KZ0F0RG3N5XT** — ADR-149: Git Repository Truth Is Forge-Agnostic _(Architecture)_
- **RAC-KZKMJ8WSMFA1** — ADR-134: Declare and Verify an Offline Materialised Parent _(Architecture)_
- **RAC-KZKMJ92ABVJG** — ADR-135: Use `corpus.source` as the Global Corpus Identity _(Architecture)_
- **RAC-KZKMJ97Z2PBE** — ADR-136: Resolve Cross-Corpus References Without Implicit Precedence _(Architecture)_
- **RAC-KZKMJ9DGR69Z** — ADR-137: Require Decision-Backed Explicit Federation Overrides _(Architecture)_
- **RAC-KZKMJ9K3AFB2** — ADR-138: Build Federation Through One Source-Aware Read Model _(Architecture)_
- **RAC-KZKMJ9RP0KNV** — ADR-139: Rank Federated Retrieval Without Source Preference _(Technical)_
- **RAC-KZKMJ9YA8BRG** — ADR-140: Apply Inherited Decisions to Child Code _(Product)_
- **RAC-KZKMJA3YK5Y1** — ADR-141: Add Bounded Federation Provenance to the Existing MCP Surface _(Product)_
- **RAC-KZKMJA9JVF6J** — ADR-142: Export the Inherited Layer by Default _(Product)_
- **RAC-KZKMJAF599TB** — ADR-143: Version Federated Generations, Cache State, and Freshness _(Technical)_
- **RAC-KZN54DB1VNPB** — ADR-144: Compose Federation as a Bounded Acyclic Source Graph _(Architecture)_
- **RAC-KZN54DB2M7FZ** — ADR-145: Declare Multiple Offline Parents Through a Versioned Federation Manifest _(Architecture)_
- **RAC-KZN54DB3V0ZC** — ADR-146: Resolve Federated Artifacts by Global Source Identity Without Precedence _(Architecture)_
- **RAC-KZN54DB4QY0R** — ADR-147: Permit Decision-Backed Override Chains Across the Federation Graph _(Architecture)_
- **RAC-KZN54DB55X9R** — ADR-148: Key Serving State to the Entire Federated Closure _(Technical)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
Expand Down
12 changes: 8 additions & 4 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: c07a39007806f42609962111a70acbc6ddc3d591c058053a0ba5e01836c031df) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 9bd32aa128aca801628967581df3ff7e0b36a1137d517b708bab47b138fe8b6f) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

Expand Down Expand Up @@ -65,6 +65,7 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KVK19NPWFYC9** — ADR-074: The Graph Export Surfaces Typed Relationship Edges _(Technical)_
- **RAC-KVNM01QPBPXB** — ADR-075: The Pre-Merge Check Tier Is a Required Merge Gate on `main` _(Process)_
- **RAC-KVSQ2A0BB9XF** — ADR-079: Note-Tool Exports Are Ingested by Normalisation, Not markitdown _(Architecture)_
- **RAC-KVSTYDARXKYW** — ADR-080: The Single Source of Truth Is Git, Not a Database _(Architecture)_
- **RAC-KVTS86ZGVJV7** — ADR-077: The Two-Gate Capture Write Model _(Architecture)_
- **RAC-KW2YW6XK593X** — ADR-084: Read-Access Audit Recorder _(Product)_
- **RAC-KW47GFBHK31W** — ADR-086: Air-Gap Posture and Enterprise Telemetry Hard-Lock _(Product)_
Expand Down Expand Up @@ -98,17 +99,20 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-KZKMJ8Q49GHV** — ADR-133: Start Corpus Federation With One Direct Parent _(Architecture)_
- **RAC-KZ0F0RG3N5XT** — ADR-149: Git Repository Truth Is Forge-Agnostic _(Architecture)_
- **RAC-KZKMJ8WSMFA1** — ADR-134: Declare and Verify an Offline Materialised Parent _(Architecture)_
- **RAC-KZKMJ92ABVJG** — ADR-135: Use `corpus.source` as the Global Corpus Identity _(Architecture)_
- **RAC-KZKMJ97Z2PBE** — ADR-136: Resolve Cross-Corpus References Without Implicit Precedence _(Architecture)_
- **RAC-KZKMJ9DGR69Z** — ADR-137: Require Decision-Backed Explicit Federation Overrides _(Architecture)_
- **RAC-KZKMJ9K3AFB2** — ADR-138: Build Federation Through One Source-Aware Read Model _(Architecture)_
- **RAC-KZKMJ9RP0KNV** — ADR-139: Rank Federated Retrieval Without Source Preference _(Technical)_
- **RAC-KZKMJ9YA8BRG** — ADR-140: Apply Inherited Decisions to Child Code _(Product)_
- **RAC-KZKMJA3YK5Y1** — ADR-141: Add Bounded Federation Provenance to the Existing MCP Surface _(Product)_
- **RAC-KZKMJA9JVF6J** — ADR-142: Export the Inherited Layer by Default _(Product)_
- **RAC-KZKMJAF599TB** — ADR-143: Version Federated Generations, Cache State, and Freshness _(Technical)_
- **RAC-KZN54DB1VNPB** — ADR-144: Compose Federation as a Bounded Acyclic Source Graph _(Architecture)_
- **RAC-KZN54DB2M7FZ** — ADR-145: Declare Multiple Offline Parents Through a Versioned Federation Manifest _(Architecture)_
- **RAC-KZN54DB3V0ZC** — ADR-146: Resolve Federated Artifacts by Global Source Identity Without Precedence _(Architecture)_
- **RAC-KZN54DB4QY0R** — ADR-147: Permit Decision-Backed Override Chains Across the Federation Graph _(Architecture)_
- **RAC-KZN54DB55X9R** — ADR-148: Key Serving State to the Entire Federated Closure _(Technical)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
Expand Down
12 changes: 8 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: c07a39007806f42609962111a70acbc6ddc3d591c058053a0ba5e01836c031df) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 9bd32aa128aca801628967581df3ff7e0b36a1137d517b708bab47b138fe8b6f) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

Expand Down Expand Up @@ -65,6 +65,7 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KVK19NPWFYC9** — ADR-074: The Graph Export Surfaces Typed Relationship Edges _(Technical)_
- **RAC-KVNM01QPBPXB** — ADR-075: The Pre-Merge Check Tier Is a Required Merge Gate on `main` _(Process)_
- **RAC-KVSQ2A0BB9XF** — ADR-079: Note-Tool Exports Are Ingested by Normalisation, Not markitdown _(Architecture)_
- **RAC-KVSTYDARXKYW** — ADR-080: The Single Source of Truth Is Git, Not a Database _(Architecture)_
- **RAC-KVTS86ZGVJV7** — ADR-077: The Two-Gate Capture Write Model _(Architecture)_
- **RAC-KW2YW6XK593X** — ADR-084: Read-Access Audit Recorder _(Product)_
- **RAC-KW47GFBHK31W** — ADR-086: Air-Gap Posture and Enterprise Telemetry Hard-Lock _(Product)_
Expand Down Expand Up @@ -98,17 +99,20 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-KZKMJ8Q49GHV** — ADR-133: Start Corpus Federation With One Direct Parent _(Architecture)_
- **RAC-KZ0F0RG3N5XT** — ADR-149: Git Repository Truth Is Forge-Agnostic _(Architecture)_
- **RAC-KZKMJ8WSMFA1** — ADR-134: Declare and Verify an Offline Materialised Parent _(Architecture)_
- **RAC-KZKMJ92ABVJG** — ADR-135: Use `corpus.source` as the Global Corpus Identity _(Architecture)_
- **RAC-KZKMJ97Z2PBE** — ADR-136: Resolve Cross-Corpus References Without Implicit Precedence _(Architecture)_
- **RAC-KZKMJ9DGR69Z** — ADR-137: Require Decision-Backed Explicit Federation Overrides _(Architecture)_
- **RAC-KZKMJ9K3AFB2** — ADR-138: Build Federation Through One Source-Aware Read Model _(Architecture)_
- **RAC-KZKMJ9RP0KNV** — ADR-139: Rank Federated Retrieval Without Source Preference _(Technical)_
- **RAC-KZKMJ9YA8BRG** — ADR-140: Apply Inherited Decisions to Child Code _(Product)_
- **RAC-KZKMJA3YK5Y1** — ADR-141: Add Bounded Federation Provenance to the Existing MCP Surface _(Product)_
- **RAC-KZKMJA9JVF6J** — ADR-142: Export the Inherited Layer by Default _(Product)_
- **RAC-KZKMJAF599TB** — ADR-143: Version Federated Generations, Cache State, and Freshness _(Technical)_
- **RAC-KZN54DB1VNPB** — ADR-144: Compose Federation as a Bounded Acyclic Source Graph _(Architecture)_
- **RAC-KZN54DB2M7FZ** — ADR-145: Declare Multiple Offline Parents Through a Versioned Federation Manifest _(Architecture)_
- **RAC-KZN54DB3V0ZC** — ADR-146: Resolve Federated Artifacts by Global Source Identity Without Precedence _(Architecture)_
- **RAC-KZN54DB4QY0R** — ADR-147: Permit Decision-Backed Override Chains Across the Federation Graph _(Architecture)_
- **RAC-KZN54DB55X9R** — ADR-148: Key Serving State to the Entire Federated Closure _(Technical)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
Expand Down
54 changes: 48 additions & 6 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,56 @@ details, release history over commit history.

## Unreleased

## v0.29.0 — 2026-08-30

### Graph-complete corpus federation

- Added manifest version 2 with one to 32 direct parents, bounded recursive
DAG verification, topology-binding `sha256-v2` pins, same-pin diamond
deduplication, deterministic cycle/divergent-pin failures, and complete
physical-route verification. Version 1 and repositories without a manifest
retain their released behavior.
- Made `corpus.source` the stable global namespace for artifacts and paths.
Source-qualified IDs, source-local aliases, legal equal IDs across sources,
and deterministic bare-reference ambiguity now share one contextual resolver.
- Added explicit Decision-backed override chains and diamond reconvergence.
Catalog history retains every original, replacement, rationale, mapping owner,
and provenance state while only the unique terminal participates in live
retrieval, relationships, path routing, and code enforcement.
- Unified validation, search, retrieval, `decisions-for`, Gate, Sentry, all six
MCP tools, cache generations, audit identity, and viewer/documents/graph
exports over the same immutable verified closure. Inherited Decisions at any
depth can govern root code; every inherited physical route remains read-only.

### Federation operators can see why

- Added `decided corpus status [directory] [--json]`. It verifies the full
closure before reporting logical sources, exact pins, canonical and physical
routes, edges, materialisation paths, graph depth, artifact projections,
overrides, and read-only boundaries. A stale or tampered route fails before
partial output.
- Added `decided corpus explain <reference> [directory] [--from source]
[--json]`. It shows contextual visibility and aliases, historical candidates,
the selected source-owned record, effective terminal, and complete ordered
override provenance; ambiguous and missing results remain machine-readable.
- Added a runnable four-source federation example with two direct parents, a
shared diamond ancestor, identical independently verified routes, and an
explicit root override.

### Git-native, not forge-dependent

- Made the architectural boundary explicit: corpus truth is reviewed Markdown
in Git, not GitHub, Cursor Origin, a branch named `main`, or a hosted database.
Federation and its stable reports work from a plain materialised tree without
`.git`, networking, a remote, or a forge API; optional review/check adapters
remain outside core semantics.
- Added versioned Draft 2020-12 schemas for the viewer, documents, and graph
export contracts. `decided export --schema <viewer|documents|graph>` emits
the packaged schema bytes offline, and CI now checks fixture and live-corpus
exports for contract and field-set drift.
- Added optional `corpus.source` configuration as the stable corpus provenance
identity shared by viewer, documents, and graph exports. Existing
repositories fall back to their lower-case `repository_key`; uninitialised
corpora retain the released directory-basename source value.
packaged schema bytes offline, and CI checks fixture and live-corpus exports
for contract and field-set drift.
- Added opt-in `decided init --parent-corpus` guidance and explicit
`decided corpus digest --version 2` pin calculation without materialising,
fetching, editing, or repinning a parent automatically.

## v0.28.0 — 2026-08-09

Expand Down
12 changes: 8 additions & 4 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ to the corpus artifact and they load through the imports below.
- Historical roadmaps: `decisions/roadmaps/archive/`
- Decisions (ADRs): `decisions/decisions/`

<!-- BEGIN RAC MANAGED BLOCK (digest: c07a39007806f42609962111a70acbc6ddc3d591c058053a0ba5e01836c031df) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 9bd32aa128aca801628967581df3ff7e0b36a1137d517b708bab47b138fe8b6f) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

Expand Down Expand Up @@ -90,6 +90,7 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KVK19NPWFYC9** — ADR-074: The Graph Export Surfaces Typed Relationship Edges _(Technical)_
- **RAC-KVNM01QPBPXB** — ADR-075: The Pre-Merge Check Tier Is a Required Merge Gate on `main` _(Process)_
- **RAC-KVSQ2A0BB9XF** — ADR-079: Note-Tool Exports Are Ingested by Normalisation, Not markitdown _(Architecture)_
- **RAC-KVSTYDARXKYW** — ADR-080: The Single Source of Truth Is Git, Not a Database _(Architecture)_
- **RAC-KVTS86ZGVJV7** — ADR-077: The Two-Gate Capture Write Model _(Architecture)_
- **RAC-KW2YW6XK593X** — ADR-084: Read-Access Audit Recorder _(Product)_
- **RAC-KW47GFBHK31W** — ADR-086: Air-Gap Posture and Enterprise Telemetry Hard-Lock _(Product)_
Expand Down Expand Up @@ -123,17 +124,20 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-KZKMJ8Q49GHV** — ADR-133: Start Corpus Federation With One Direct Parent _(Architecture)_
- **RAC-KZ0F0RG3N5XT** — ADR-149: Git Repository Truth Is Forge-Agnostic _(Architecture)_
- **RAC-KZKMJ8WSMFA1** — ADR-134: Declare and Verify an Offline Materialised Parent _(Architecture)_
- **RAC-KZKMJ92ABVJG** — ADR-135: Use `corpus.source` as the Global Corpus Identity _(Architecture)_
- **RAC-KZKMJ97Z2PBE** — ADR-136: Resolve Cross-Corpus References Without Implicit Precedence _(Architecture)_
- **RAC-KZKMJ9DGR69Z** — ADR-137: Require Decision-Backed Explicit Federation Overrides _(Architecture)_
- **RAC-KZKMJ9K3AFB2** — ADR-138: Build Federation Through One Source-Aware Read Model _(Architecture)_
- **RAC-KZKMJ9RP0KNV** — ADR-139: Rank Federated Retrieval Without Source Preference _(Technical)_
- **RAC-KZKMJ9YA8BRG** — ADR-140: Apply Inherited Decisions to Child Code _(Product)_
- **RAC-KZKMJA3YK5Y1** — ADR-141: Add Bounded Federation Provenance to the Existing MCP Surface _(Product)_
- **RAC-KZKMJA9JVF6J** — ADR-142: Export the Inherited Layer by Default _(Product)_
- **RAC-KZKMJAF599TB** — ADR-143: Version Federated Generations, Cache State, and Freshness _(Technical)_
- **RAC-KZN54DB1VNPB** — ADR-144: Compose Federation as a Bounded Acyclic Source Graph _(Architecture)_
- **RAC-KZN54DB2M7FZ** — ADR-145: Declare Multiple Offline Parents Through a Versioned Federation Manifest _(Architecture)_
- **RAC-KZN54DB3V0ZC** — ADR-146: Resolve Federated Artifacts by Global Source Identity Without Precedence _(Architecture)_
- **RAC-KZN54DB4QY0R** — ADR-147: Permit Decision-Backed Override Chains Across the Federation Graph _(Architecture)_
- **RAC-KZN54DB55X9R** — ADR-148: Key Serving State to the Entire Federated Closure _(Technical)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
Expand Down
16 changes: 16 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,22 @@ decisions/
Existing artifact IDs such as `RAC-ABC123DEF456` are durable identities and do
not change with the product name.

## Federate corpora

Manifest version 2 composes several pinned, materialised parent corpora into
one source-aware DAG while preserving every source, diamond route, override,
and read-only boundary:

```sh
decided corpus status decisions/
decided corpus explain organization/standards::ADR-01K000000001 decisions/
```

Federation is fully offline and forge-neutral: the engine consumes verified
working-tree bytes, not GitHub APIs or a hosted index. See the
[federation guide](docs/federation.md) and
[runnable multi-parent example](examples/federation/).

## Migrate an existing repository

Migration is explicit and never runs during an ordinary command:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
---
schema_version: 1
id: RAC-KVSTYDARXKYW
type: decision
---
# ADR-080: The Single Source of Truth Is Git `main`, Not a Database
# ADR-080: The Single Source of Truth Is Git, Not a Database

## Context

Expand Down Expand Up @@ -67,7 +67,11 @@

## Status

Proposed
Accepted

ADR-149 preserves this decision's no-database, Git-backed source-of-truth
contract while amending its hard-coded Git-host `main` branch language with a
forge-, remote-, and branch-name-neutral repository contract.

## Category

Expand Down Expand Up @@ -96,6 +100,7 @@
- adr-065
- adr-066
- adr-073
- adr-149

## Related Roadmaps

Expand Down
Loading
Loading