Skip to content

SOW v0.1 Decision Ledger: What Survived and What Was Retired

A curated ledger of all 44 surviving v0.1 ADR files, the problem each addressed, and whether its decision survived, evolved, became migration-only, or retired with V1.
Historical decision ledger

The v0.1.0 tag contains 44 ADR files numbered 0001 through 0045; 0006 is absent. This page preserves their meaning without republishing each historical implementation contract as current guidance.

An ADR is valuable even when its implementation is retired. It records the failure mode the team refused to ignore, the boundary selected at the time, and often the evidence required before a dangerous operation could proceed.

The table below classifies each decision into four fates:

Fate Meaning
Retained The principle remains part of current SOW with substantially the same boundary.
Evolved The problem and safety rule survived, but ownership or implementation changed.
Migration history The decision governed a one-time Pigsty/V1 cutover and is no longer a product contract.
Retired The decision belonged to the Git/CAS/Route/Edge product model removed from current SOW.

Primary decision dates run from 2026-07-11 through 2026-07-28; ADR-0035 carries later amendments on July 29 and July 31. Most early ADRs were consolidated into Git on July 19 after already being used by implementation and evidence work. The v0.1.0 tag tree was checked to contain the same 44 ADR paths represented below. One raw link is intentionally omitted because the historical record names obsolete infrastructure details.

Core state, publication, and trust

ADR Original decision Later fate
0001 Git was canonical state, SHA-256 CAS owned package bytes, refs expressed views/history, and publication used target sagas. Evolved. Git/CAS/Route ownership retired; single ownership, pointer-last publication, independent target state, and evidence gates survived.
0002 Public routes, immutable generations, and client/provider compatibility had separate acceptance gates. Evolved. Route machinery retired; protocol/client/provider evidence remains separate.
0003 Snapshots required verified generation copies and inventory-bound retention. Evolved. CopyObject snapshot trees retired; retained generations now store metadata and reference sets without payload copies.
0004 Edge token verification and deployment had one versioned cross-provider contract. Retired. Edge entitlement is no longer part of the SOW repository engine.
0005 Every legacy Make target was mapped to SOW, retirement, or policy rejection. Migration history. The mapping completed its cutover role and left the active product.
0007 Public and gated packages shared one canonical repository instead of a separate Pro bucket. Retired. The commercial Edge topology left product scope; the more general single-owner lesson remains.
0008 GC followed complete reachability and required explicit confirmation for destructive work. Retained. Current local and target GC still require closure, exact identity, grace, and capability.
0009 Once a remote generation became visible, recovery rolled forward rather than inventing rollback. Retained. Commit intent remains the boundary between abandon/reconcile and forward-only recovery.
0010 Metadata signing bound exact public/private identities and treated rotation as a repository-wide transition. Evolved. Current signer evidence and trust-ring rules preserve exact identity without the V1 ref topology.
0011 Remote deletion required target ownership, inventory, checkpoint, grace, and conditional-delete evidence. Retained. R2 remains report-only because it cannot satisfy the required atomic delete capability.
0012 Private origins, cache topology, and exact purge mapping were explicit deployment contracts. Retired. CDN/private-origin deployment is outside current SOW.
0013 A persisted plan was recovery input to revalidate, never authority to replay blindly. Retained. Managed recovery still rebinds plans, files, target identity, and public evidence.
0014 RPM provenance recorded exact packet evidence and distinguished ingestion policy from historical proof. Evolved. Current package authentication and independent trust rings replace the V1 receipt encoding.
0015 Configuration named a target; published refs and checkpoints belonged to canonical state. Retained. Target-neutral generations and target-prefix attempts/checkpoints remain separate owners.
0016 Cloud adapters used concrete, bounded SDK/API contracts instead of a generic provider abstraction. Evolved. Concrete provider boundaries survived; V1 Edge/COS details retired.
0017 Accepted RPM signatures had to close against a stable repository keyring and opened payload identity. Evolved. v0.4 independent multi-ring verification strengthens the same trust boundary.
0018 A selected package set staged, validated, committed, and recovered as one bounded local transaction. Evolved. V1 materialization retired; current Plain/Managed pointer-last staging keeps the transactional lesson.

Legacy topology, compatibility, and migration

ADR Original decision Later fate
0019 EL7 metadata format and compressor behavior were frozen for legacy consumers. Migration history. Current compatibility documentation, not this freeze, defines supported platforms.
0020 Every legacy physical path and selector group received an explicit owner. Migration history. It prevented ambiguous cutover but is not a current repository model.
0021 Cross-EL yum/infra/{arch} projections were reproduced with exact frozen evidence. Migration history. The special projection left active product scope.
0022 Package history could not be broken merely because physical ownership moved. Evolved. Generations, retained references, and migration journals now preserve continuity without V1 routes.
0023 Canonical Git objects were rebound to exact bytes before admission and use. Evolved. Git authority retired; descriptor/path/digest identity checks remain.
0024 Materialized route receipts acted as narrow read/retirement capabilities. Evolved. Route receipts retired; capability-bound inspection and deletion survived.
0025 Locks bound an exact process instance and stable lock inode rather than elapsed time. Evolved. Stable lock inodes and rejection of timeout-based lock stealing survived; the V1 process-instance lease mechanism did not.
0026 Offline archive creation used a durable intent and strict archive admission. Retired. Offline archive projection left current SOW scope.
0027 Legacy bytes entered canonical state only after exact path, package, and provenance admission. Migration history. The adoption program completed; strict package admission remains in narrower form.
0028 DEB inspection opened only the control archive needed for metadata and rejected ambiguous containers. Retained. Narrow parsing and bounded input remain part of the APT package boundary.
0029 Client floors and the EL8 freeze were explicit owner policy, not inferred from code. Migration history. Current platform policy lives in the compatibility reference and release notes.
0030 Missing legacy YUM bodies could be repaired only from a reviewed blocker-set digest. Migration history. The narrow negative-provenance exception did not become a general ignore flag.
0031 Gated legacy content required exact checksum repair and activation evidence. Retired. Pro activation left product scope; fail-closed repair remained a general lesson.

Provider and Edge control plane

ADR Original decision Later fate
0032 Only one exact owner-designated Cloudflare test tuple could bypass normal production rejection. Retired. It was a narrow historical test exception, never a general deployment rule.
0033 Read-only provider readiness had its own registry and ownership evidence. Retired. Provider bootstrap registry left current SOW.
0034 Worker bootstrap used leases, two-phase recovery, exact resources, and reversible state. Retired. Cloudflare deployment is no longer repository-engine responsibility.
0035 Provider identity, runtime bindings, log sink, and lease ownership were attested before use. Retired. The exact Edge control plane left product scope.
0036 R2 lacked conditional DeleteObject, so an explicit checkpoint-fenced unconditional-delete fallback was allowed behind a deterministic capability probe and repeated identity/fence proofs. Evolved; fallback not inherited. Capability probing and fail-closed defaults survived, but current SOW disables R2 remote deletion and keeps target GC report-only.
0037 Gated publication had to prove denial at the Edge before uploading confidential bytes. Evolved. The Edge product surface retired; proving authorization before exposure survived.
0038 YUM cutover required an expiring receipt bound to exact endpoints, generation, and trust bytes. Migration history. It made a dangerous consumer cutover auditable and then retired.
0039 Caret had one canonical URL spelling across Go, Edge, logs, and origin routing. Evolved. The route was retired; canonical encode-once path handling remains.

Bounded configuration and derived-state recovery

ADR Original decision Later fate
0040 Configuration cardinality and expanded topology were bounded before allocation or execution. Retained. Current parsers and state wires keep explicit size/cardinality limits.
0041 Unknown final projection stages were preserved for audit rather than guessed away. Evolved. Current recovery still preserves contradictory evidence and fails closed.
0042 Derived-state replacement had explicit success, rollback, preserved, and blocked outcomes. Retained. Current operations report precise recovery outcomes instead of collapsing them into success/failure.
0043 File mutation bound descriptor identity and stated the same-UID hostile-writer limit honestly. Retained. Path safety still fails closed without claiming protection outside its OS ownership boundary.
0044 Preserved audit copies could be retired only through an exact capability and confirmation token. Evolved. The V1 command retired; exact capability-bound deletion remains a design rule.
0045 Unjournaled residue had a bounded classifier and could never be silently adopted or deleted. Retained. Current recovery distinguishes known state, safe residue, and contradictory evidence.

The pattern behind the ledger

The decisions that survived were not the most elaborate V1 mechanisms. They were the small invariants beneath them:

  • one owner for each fact;
  • exact identity before mutation;
  • immutable preparation before pointer commit;
  • forward recovery after commit intent;
  • complete evidence before deletion;
  • explicit bounds and honest non-goals;
  • compatibility claims attached to the client/provider actually tested.

The Git database, route graph, Edge bootstrap, and migration commands were replaceable. These invariants were not. They are maintained today in Design Principles, System Model, and Publication & Recovery.

The v0.1.0 ADR directory remains the immutable primary source. The next article summarizes the separate v0.1 evidence record.