Implement and audit the secondary-index industrial foundation - #55
Merged
Conversation
forhappy
marked this pull request as ready for review
July 30, 2026 00:43
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Implements the approved hard-cutover secondary-index industrial foundation and
the 2026-07-29 final architecture audit. This is the implementation follow-up
to merged planning PR #52.
The cutover adds no compatibility reader, dual publication, migration shim, or
suffix-named V2/V3 API.
Architecture and correctness
IndexedCollectionStateroot and one CAS linearization point.retention, and durable pins.
work local instead of scanning or rebuilding complete collections.
durable pins.
FileNodeStore,MemStore,PGlite, redb, RocksDB, and SlateDB remain explicitly verification-only.
Bounded resources
source fetches, retained memory, scans, and elapsed time.
verify_allbudgeting.Diagnostics and release gates
Debug/Displaycontract and stable index code/retry metadatathrough UniFFI, Kotlin, Python, Ruby, Swift, and WASM.
docs/secondary-index-release-evidence.md.Local validation
Final audit verdict
The atomic core is strong and the implementation is materially hardened. This
PR is intentionally a draft because production certification still requires:
durability evidence;
baselines.
The required CI results must also pass on the exact PR head before release.