Skip to content

fix(mcp): re-check type-override rationales on every version-1 request [roadmap:deterministic-substrate] - #499

Merged
tcballard merged 3 commits into
mainfrom
claude/rationale-freshness
Sep 25, 2026
Merged

tcballard merged 3 commits into
mainfrom
claude/rationale-freshness

Conversation

@tcballard

@tcballard tcballard commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This closes the known limitation recorded in #495.

A type override's rationale Decision may resolve outside the captured version-1 snapshot: #495 made root-owned rationales resolve across the root's whole working tree. The version-1 FederatedCacheTracker warm path skips recomposition while the captured generation is unchanged. As a result, a cached decided-mcp kept serving after that Decision was retired, while a fresh process correctly failed with corpus-federation-invalid-override.

While any type override is applied, the version-1 tracker now recomposes on every request, which is what the version-2 tracker already does for every request. Corpora without type overrides keep the warm path unchanged.

Version 2 had no gap: GraphFederatedCacheTracker::read_or_recompose runs compose_verified_federation, including the rationale check, on every request.

Roadmap / ADR Trace

  • Roadmap: decisions/roadmaps/deterministic-substrate.md (Tranche C)
  • ADR-150 (type-override rationales), ADR-112 (freshness floor), ADR-148 (serving generation keys)

Scope

  • rust/rac-engine/src/derived_cache.rs: one condition on the v1 warm path.
  • rust/decided-mcp/tests/spec_registry_freshness.rs: regression test.
  • docs/validation.md, CHANGELOG.md.

Product / Architecture Decisions

  • Recomposing per request while overrides are applied was chosen over plumbing the resolved rationale file into the generation's watched files. The resolved path is only known after composition, but the generation is captured before it, so watching it would need a second, post-build freshness input. Type overrides are rare, and the cost matches what every version-2 server already pays.

User-Facing Contract

  • A retired or removed rationale Decision now fails the next cached request (corpus-federation-invalid-override … not a live Decision) instead of being noticed only after a restart.
  • No other behaviour change. The warm path is untouched for corpora without type overrides.

Verification

  • cargo fmt --check; cargo clippy --workspace --release --no-deps -- -D warnings and --all-targets: clean; cargo test --workspace --release: pass.
  • Mutation check: without the fix, the new test's third get_summary succeeds (the stale model is served), so the test fails.
  • Conformance 11/11; live-corpus invariants PASS; corpus gates exit 0.

Review Path

  1. derived_cache.rs (8 lines).
  2. The test.

Notes For Reviewer

Implementation Process

Implemented with AI assistance under the roadmap contract; final scope, review, and acceptance decisions were made by the maintainer.

…t [roadmap:deterministic-substrate]

Implements decisions/roadmaps/deterministic-substrate.md (Tranche C).

A type override's rationale may resolve outside the captured version-1
snapshot (the root's whole working tree), so the warm path, which skips
recomposition while the generation is unchanged, kept serving after that
Decision was retired. While any type override is applied the tracker now
recomposes each request, as the version-2 tracker always does.
…deterministic-substrate]

Implements decisions/roadmaps/deterministic-substrate.md (Tranche C).

A version-1 server whose type override cites a Decision in docs/, outside
the served decisions/ root, fails the next cached request once that
Decision is retired.
…istic-substrate]

Implements decisions/roadmaps/deterministic-substrate.md (Tranche C).
@tcballard
tcballard force-pushed the claude/rationale-freshness branch from 6d14fa7 to 2d24108 Compare September 25, 2026 13:31
@tcballard
tcballard merged commit ddd65ef into main Sep 25, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant