ADR 004 — Independent oracle and bounded verification¶
Status: independent oracle and bounded verifier implemented; manual and owned-pipeline relay drain/handoff · updated 3 October 2026
Context¶
Agreement between two computations is weak evidence if they reuse the same faulty logic or describe different input prefixes. An empty outbox does not establish that downstream state has been applied.
Decision¶
Implement a separate full-history oracle that reconstructs authority and business state from retained source records. It must not call the incremental resolver, fold, or diff, or use the worker's applied-state tables as its input. Validate both paths against small hand-stated expectations.
The implemented first verifier awaits the owned finite source loader and holds producer/relay session guards. The operator drains and stops/joins the relay before handing off. The command captures a source prefix, requires processing and publication to have reached it, captures the output boundary, waits for the view, and compares a stable snapshot. The showcase runner automates this handoff for its fresh, owned finite pipeline. Manually run pipelines still require the operator handoff. Session guards alone cannot prove uncertain orphan broker requests have drained; a clean handoff remains an explicit operating precondition. Include namespace/configuration, source/output frontiers, diagnostics, and completion status in the report.
S10 clarification, 29 September 2026: when an incomplete boundary and known source conflicts coexist, report INCOMPLETE with those conflicts still visible. Keep affected keys BLOCKED. Once the complete boundary is established, unresolved authority produces overall BLOCKED. Reporting BLOCKED first would hide that the comparison boundary is still incomplete; retaining conflict diagnostics keeps the authority problem visible throughout.
Alternatives¶
A shared batch/incremental fold reduces code but can make the same defect invisible on both sides. Uncoordinated live reads can confuse normal progress with drift. True online prefix verification would need historical snapshot or cut mechanics beyond an unversioned current view.
Consequences¶
Verification is an operator capability as well as a test. It can return PASS, PASS_WITH_EXCLUSIONS, BLOCKED, DRIFT, INCOMPLETE, or ERROR. Explicitly expected poison-input diagnostics may qualify a test result; unknown exclusions never become a silent clean pass.
Retained full history and stable configuration are correctness dependencies. Independent implementation reduces correlated defects but does not constitute exhaustive proof.
Review trigger¶
Add live verification only when its snapshot boundary is specified and independently tested. Do not substitute a racing pair of reads for that protocol.