Change a Live Index Without Changing Its Promises

Plan a derived-index migration with coherent backfill, committed replay, checked routing, current-boundary rollback and explicit cleanup obligations.

The new index has finished its scan. Its dashboard says backfill complete. While it was scanning, a document was replaced and then deleted. The new generation has replayed the replacement, but its worker has not applied the delete.

Would you switch production reads to it? Predict the exact wrong document version that would appear, and the state you need before the switch can preserve the existing answer.

This decision extends the visibility chapter: we now build a second derived-index format while the same writer keeps committing updates. The answer contract stays fixed. Later we will need to roll back, release an older reader and reclaim the old generation. Each step creates a separate obligation.

Evidence boundary: This is an explicit synthetic protocol with one fixed authority and two derived generations. Its ordered records, coherent snapshot, receipts, replay, readiness checks and routing transaction are stipulated. Official documentation supplies comparisons within its product and configuration scope. No migration, load test, production availability check or benchmark was run. The event controls show causal steps, not elapsed time.

Reading time covers the lesson’s prose and main trace; the complete transcript and exercises take additional time.

Name the promise before changing the format

Our recurring engineering-document service ranks tenant A’s live documents. A query selects one vector field, body, with one vector per document. Lower squared Euclidean distance wins, then lower document ID breaks ties. We request k=2 distinct documents and project the same winning versions. The tenant comes from trusted identity context; current-policy disclosure authorization remains a separate decision.

Generation A uses the old physical index format. Generation B uses the proposed format. Both must implement this same answer function at the same selected boundary. The fixture supplies distances directly; it does not implement an ANN algorithm or reconstruct embeddings. Its exact paper answers do not establish production ANN completeness.

Changing an embedding or scoring model changes what the answer function means. That needs the separate evidence and launch decision lesson: preserved result IDs are no longer an adequate goal. Here we change the derived format while preserving the declared function.

A migration plan must also state availability and freshness behavior. This exercise uses a generation-only read path. A current query selects S=D and requires the routed generation to cover it. If coverage or required artifacts are missing, or the query path is unhealthy, it returns an explicit error with no IDs. It never silently lowers S or consults an authority tail. An implementation with another fallback path needs that path’s own stated contract.

A scan boundary is not a routing decision

The writer assigns increasing positions and increasing per-document versions. Only committed records participate. A replace contains the document’s complete searchable state; a delete creates a tombstone, a version barrier that suppresses older copies. An identical request-ID/payload retry returns its original durable receipt and creates no new commit.

Separate six facts:

LabelWhat it meansWhat it cannot establish by itself
D, authorityCurrent committed boundary of the fixed writer.A derived generation has applied every committed change.
B, coherent backfill snapshotOne stable corpus boundary used for construction. Here B=22.A completed scan includes commits after22.
I_A / I_B, publicationCursor of each active immutable published base.The generation has no applied tail, or its query path is healthy.
C_A / C_B, coverageLargest complete prefix of the committed sequence represented durably by snapshot plus applied records.A maximum observed replay position proves a complete prefix.
S, reader selectionBoundary chosen for this query. Current S=D; the held reader pins S22.A different reader needs the same answer or base.
Route and revisionDefault/canary generation chosen by committed metadata.The destination is compatible, covered or available.

The committed sequence here is [20,21,22,23,24,26,27]. Position25 will be written but never committed. Coverage can advance from24 to26 and27 without applying25. Conversely, a worker that applies27 while omitting committed24 still has a hole: its complete prefix ends at23. “Largest position seen” loses exactly the information the gate needs.

For this finite protocol, a snapshot is coherent and connected to retained committed replay after its boundary. Debezium’s PostgreSQL3.3 connector documentation describes an initial snapshot followed by streaming from the recorded log position. Its snapshot workflow and isolation configuration also qualify whether reads see a single consistent version. The comparison explains why a boundary must connect scan and replay; it does not make every scan configuration coherent or establish our consumer/routing protocol.

Keep the complete input visible

We reuse the visibility chapter’s recovery fixture, where replacement23 has distance0.05. Records26 and27 are synthetic extensions for the migration decision. The initial snapshot22 contains positions20–22. Every record needed for this fixed query is below; a delete has no vector distance.

positiondoc_idversiontenantoperationdistanceauthorityrequest_idpayload_fingerprint
2071Areplace0.10committedinitial7Hinitial7
2181Areplace0.20committedinitial8Hinitial8
2291Areplace0.20committedinitial9Hinitial9
2372Areplace0.05committedblue7Hblue
2473Adelete-committedremove7Hremove
2574Areplace0.01written-onlygreen7Hgreen
2682Areplace0.03committedupdate8Hupdate8
27101Areplace0.15committedinitial10Hinitial10

Resolve the latest committed version at S for each document, including deletes, before ranking live eligible documents. Exclude written-only25 even though its distance is attractive. A published compacted base keeps each document’s latest live record or deletion barrier through I; its coverage represents the complete committed prefix, not only the surviving record positions or top-k hits.

Check the required exact answers before following the migration
Sdoc7_versiondoc7_stateexact_idsexact_versionsdistances
221live[7,8][1,1][0.10,0.20]
232live[7,8][2,1][0.05,0.20]
243deleted[8,9][1,1][0.20,0.20]
263deleted[8,9][2,1][0.03,0.20]
273deleted[8,10][2,1][0.03,0.15]

Doc8 precedes doc9 in the0.20 tie. At27, doc10 displaces doc9; doc7 stays deleted. The held reader’s independent manual S22 reference is [7v1,8v1]. Comparing that historical response to the current S27 oracle [8v2,10v1] would manufacture a mismatch. A released or unavailable reader delivers no IDs even when its historical teaching reference remains visible.

A pass reproduces each winning version, delete barrier, tie and result order from the supplied records. It does not infer a result from a route label or an index cursor alone.

Finish the backfill, then close the committed gap

AtM00, A has I22/C22 and serves the default route. One old reader pins A-base-22/S22. M01 starts a partial B scan at the same coherentB22. That partial seed is not valid and has no coverage cursor.

The writer commits replacement23 atM02; A applies it. B’s worker stalls atM03. The writer commits delete24 atM04 and A applies it. M05 writes25 without commitment. AtM06 an identical late blue7/Hblue retry returns receipt23 after the delete. The receipt identifies the original operation; it does not make doc7v2 live again.

M07 resumes B and finishes its coherent snapshot22. B now has I22/C22, while current D=S24 requires replay23 and24. M08 delivers23 twice: the generation applies the immutable record once, leaving I22/C23. The first missing committed position is24.

Debezium’s crash behavior explains that resuming from the last recorded offset can generate duplicate change events and consumers should anticipate them. Our idempotent record application follows a declared toy rule. The separate client request receipt contract is also stipulated; change-stream duplicate handling does not establish an API’s retry semantics.

A complete scan can still omit a committed delete

Authority and maintained A

  1. Pin B22 and old readerS22

    A publishes I22 and covers C22. The held reader retains A-base-22 and its versioned projections.

  2. Commit replacement23, then delete24

    A applies both records and reaches C24. Written-only25 has no authority. Late retry returns receipt23.

  3. Keep current S24

    DefaultA resolves doc7v3 deleted, then returns8v1 and9v1. Its held S22 reader still needs7v1 and8v1.

Candidate B and guarded cutover

  1. Finish coherent snapshot22

    The scan is complete and valid. I22/C22 still omits post-snapshot committed records.

  2. Replay23 twice, omit24

    Idempotent application gives C23. A maximum offset or completed scan cannot supply the deletion barrier.

  3. Reject target24 atM09

    ERROR_COVERAGE_GAP identifies missing24. Replay24 before checking exposure and publishing a route.

Synthetic fixed-writer protocol. Both generations preserve one answer contract. B22 is the scan boundary; I/C/S and route remain separate. No elapsed-time or production availability promise is drawn.

The trace’s current answer remains [8v1,9v1] through the rejected switch. A completed B scan plus replacement23 would instead expose deleted doc7v2 if forced to answer from its stale state. A scan-completion flag is therefore an input to readiness, not permission to publish routing.

Check the opening cutover prediction

AtM09, B I22/C23 cannot serve selectedS24: committed delete24 is missing. The guarded action returns ERROR_COVERAGE_GAP with missing[24] and keeps defaultA. Its current response is [8v1,9v1] atS24.

The forced stale diagnostic from B at its actualS23 is [7v2,8v1], distances0.05/0.20. It includes deleted7 and misses9 at requiredS24. It is never relabeled as a freshS24 delivery. Dropping7 from a truncated stale top2 would leave only8; complete reconciliation/candidate coverage is needed to recover9.

The minimal repair is to replay committed24, keeping its doc7v3 barrier. B reaches C24 while I remains22 and can answer S24 from its published base plus complete applied tail. Publishing B-base-24 atM11 then advances I24; it changes the representation, not the answer. A pass names the missing operation, wrong version and missing ID, and preserves the selected boundary.

Backfill, coverage and routing are separate decisions

Follow a synthetic fixed-writer index-format migration. The current query selects S=D; a held reader keeps S22. Each manual step is an event boundary, not elapsed time. One body vector per live document, squared Euclidean ascending then doc ID, k=2.

Predict which generation can answer the selected S, which versions win, and what must remain for the held reader or rollback.

M00: Serve A and pin an older reader

M00: D22, backfill B22, current selected S22 D — committed 22 B — coherent scan 22 S — selected reader 22

Committed records [20, 21, 22]; written-only records []. Position25 never joins the committed sequence.

Generation A

I=22 · C= 22

valid; worker running; healthy.

Snapshot coverage [20, 21, 22]; applied tail [].

First missing committed position: none.

Active base: A-base-22.

Generation B

I=none · C= none

absent; worker not-started; unhealthy.

Snapshot coverage []; applied tail [].

First missing committed position: incomplete snapshot.

Active base: none.

Routing revision0: defaultA; canary absent.

Held reader pins A-base-22/S22; A rollback window open.

Try M09's cutover, M19's rollback and M15's premature cleanup. Then apply23/26/27 while omitting delete24: does maximum position27 establish C27? The complete answers below remain available without JavaScript.

Complete migration transcript: all31 events and four query paths

D is authority; B is the coherent snapshot; I is the published immutable base; C is complete coverage of the committed sequence; S is the query's selection. Committed positions are20,21,22,23,24,26,27. Written-only25 is excluded. Current references follow D; the held reader's independent manual reference stays [7v1,8v1] atS22.

  1. M00: Serve A and pin an older reader

    A serves snapshot 22. The held reader pins A-base-22 and S22; later commits do not change that selection.

    Action: INITIALIZED. Serve A and pin an older reader.

    D=22; B=22; committed [20, 21, 22]; written-only []. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=22; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail []; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1].

    Generation B: publication and coverage

    I=none; C=none; absent; backfill incomplete; worker not-started; query path unhealthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    Retained artifacts: [].

    Current default route

    Selected S=22; generation A; I=22, C= 22. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

    Canary route

    Selected S=22; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=22; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 22. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  2. M01: Start B from coherent snapshot 22

    A partial scan of one document is not a valid B snapshot, so B has neither I nor C.

    Action: BACKFILL_PARTIAL. Start B from coherent snapshot 22.

    D=22; B=22; committed [20, 21, 22]; written-only []. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=22; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail []; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=22; generation A; I=22, C= 22. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

    Canary route

    Selected S=22; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=22; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v1, 8v1] at S=22. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 22. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  3. M02: Commit replacement 23 while backfill runs

    The fixed writer commits replacement 23. A receives it; B's coherent snapshot remains pinned at 22.

    Action: COMMITTED. Commit replacement 23 while backfill runs.

    D=23; B=22; committed [20, 21, 22, 23]; written-only []. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=23; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=23; generation A; I=22, C= 23. Status OK; missing committed positions [].

    Actual delivered response: [7v2, 8v1]; distances [0.05, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    • doc7 v2: live; position23; distance 0.05.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v2, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v2, projection-8-v1].

    Canary route

    Selected S=23; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=23; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 23. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  4. M03: Stall the B backfill worker

    Stalling the B worker changes progress, not authority or routing.

    Action: WORKER_STALLED. Stall the B backfill worker.

    D=23; B=22; committed [20, 21, 22, 23]; written-only []. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=23; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=23; generation A; I=22, C= 23. Status OK; missing committed positions [].

    Actual delivered response: [7v2, 8v1]; distances [0.05, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    • doc7 v2: live; position23; distance 0.05.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v2, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v2, projection-8-v1].

    Canary route

    Selected S=23; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=23; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [7v2, 8v1] at S=23. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 23. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  5. M04: Commit delete 24 while B is stalled

    Delete 24 becomes authoritative. A can answer S24; B has not acquired the delete.

    Action: COMMITTED. Commit delete 24 while B is stalled.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only []. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  6. M05: Write replacement 25 without authority commitment

    Replacement 25 exists only as written data. It has no committed receipt, no authority and no route visibility.

    Action: WRITTEN_ONLY. Write replacement 25 without authority commitment.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  7. M06: Retry old replacement after deletion

    The identical blue7/Hblue retry returns receipt23, even after delete24. It creates no new commit or resurrection.

    Action: ORIGINAL_RECEIPT. Identical blue7/Hblue retry returns original receipt23; no new commit or resurrection.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=none; C=none; building; backfill incomplete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    • B-partial-22, cursor22: latest per-document record positions [20].

    Retained artifacts: [generation-B].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=none, C= none. Status ERROR_GENERATION_NOT_VALID; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  8. M07: Resume B and finish snapshot 22

    Backfill complete means a valid snapshot of B22. Current S24 still requires committed replay23 and24.

    Action: BACKFILL_COMPLETE. Resume B and finish snapshot 22.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=22; C=22; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail []; active base B-base-22.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=22, C= 22. Status ERROR_COVERAGE_GAP; missing committed positions [23, 24].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  9. M08: Replay replacement 23 twice

    Two deliveries of record23 persist one application. The delete at24 is still missing, so C23 and I22 remain distinct.

    Action: REPLAYED_IDEMPOTENTLY. Apply inputs23,23 once and ignore the duplicate23 delivery.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=22; C=23; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23]; active base B-base-22.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=22, C= 23. Status ERROR_COVERAGE_GAP; missing committed positions [24].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  10. M09: Reject cutover with missing delete 24

    Cutover target24 is rejected before exposure gates because missing24 violates coverage. Current route A remains correct. The forced stale counterexample [7v2,8v1] is a diagnostic at S23, not an S24 response.

    Action: ERROR_COVERAGE_GAP. Reject cutover with missing delete 24. Missing committed positions: 24. Route unchanged.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=22; C=23; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23]; active base B-base-22.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=22, C= 23. Status ERROR_COVERAGE_GAP; missing committed positions [24].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  11. M10: Replay the committed delete

    The committed delete creates the v3 barrier. B C24 can answer current S24 from base22 plus its applied tail, even before I advances.

    Action: REPLAYED. Replay the committed delete.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base B-base-22.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-22, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  12. M11: Publish immutable B base 24

    Published B-base-24 preserves the v3 tombstone barrier as well as live documents. Publication moves I24; coverage was already C24.

    Action: BASE_PUBLISHED. Publish immutable B base 24.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=24; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail []; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  13. M12: Check exact IDs, versions and full projected state at 24

    The finite shadow gate checks full winning-record state, exact IDs, versions, distances and projection keys at the same S24. This is not a workload canary measurement.

    Action: SHADOW_PASSED. Check exact IDs, versions and full projected state at 24.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 0: defaultA, canary absent. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=24; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at none .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail []; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation none; I=none, C= none. Status ERROR_NO_CANARY_ROUTE; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  14. M13: Expose and check the canary at 24

    A stipulated healthy, compatible, covered B query path passes the finite exposure check. The canary route becomes B; default remains A.

    Action: CANARY_PASSED. Expose and check the canary at 24.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 1: defaultA, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=24; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail []; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  15. M14: Fail routing publication before metadata commit

    The injected failure is known to occur before metadata commit. Route revision1 and defaultA/canaryB remain unchanged. An ambiguous timeout would require a separately defined resolution protocol.

    Action: ERROR_ROUTING_WRITE_FAILED. Fail routing publication before metadata commit. Known precommit failure; routing revision1/defaultA/canaryB unchanged.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 1: defaultA, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=24; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail []; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24].

    Current default route

    Selected S=24; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  16. M15: Switch the default route to checked B

    Readiness and boundary24 are rechecked inside the stipulated atomic metadata action. Default and canary now select B. A remains maintained and pinned-reader artifacts stay retained.

    Action: CUTOVER_PUBLISHED. Switch the default route to checked B.

    D=24; B=22; committed [20, 21, 22, 23, 24]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2].

    Generation B: publication and coverage

    I=24; C=24; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail []; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24].

    Current default route

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Canary route

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Direct candidate B diagnostic

    Selected S=24; generation B; I=24, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [8v1, 9v1]; distances [0.20, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v1, 9v1] at S=24. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v1, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v1, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 24. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  17. M16: Maintain both generations through committed 26

    Authority skips written-only25 and commits26. Both A and B cover the committed prefix through26; B still publishes I24.

    Action: COMMITTED. Maintain both generations through committed 26.

    D=26; B=22; committed [20, 21, 22, 23, 24, 26]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=26; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2].

    Generation B: publication and coverage

    I=24; C=26; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2].

    Current default route

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Canary route

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Direct candidate B diagnostic

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  18. M17: Stall retained A maintenance

    A files remain retained, but its maintenance worker stops. Retention alone does not promise current-boundary rollback readiness.

    Action: WORKER_STALLED. Stall retained A maintenance.

    D=26; B=22; committed [20, 21, 22, 23, 24, 26]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=26; valid; backfill complete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2].

    Generation B: publication and coverage

    I=24; C=26; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2].

    Current default route

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Canary route

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Direct candidate B diagnostic

    Selected S=26; generation B; I=24, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 9v1]; distances [0.03, 0.20]. Exact paper answer at its selected S.

    Required reference: [8v2, 9v1] at S=26. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-8-v2, projection-9-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-9-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  19. M18: Commit insertion 27; only B catches up

    Only B applies insertion27. A remains C26 while current S=D27. The held A reader can still read its separate S22 selection.

    Action: COMMITTED. Commit insertion 27; only B catches up.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=26; valid; backfill complete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  20. M19: Reject rollback to retained but undercovered A

    Rollback to A is rejected for missing27. DefaultB remains correct. A forced stale answer [8v2,9v1] would miss10 and include9 outside exact top2 at S27.

    Action: ERROR_COVERAGE_GAP. Reject rollback to retained but undercovered A. Missing committed positions: 27. Route unchanged.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=26; valid; backfill complete; worker stalled; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 26. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  21. M20: Resume A and apply 27

    A's maintenance/read capability resumes and replay27 restores coverage through27. Its published I22 plus applied tail is sufficient; I need not equal D for rollback readiness.

    Action: REPLAYED. Resume A and apply 27.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  22. M21: Make the active B query path unhealthy

    B is covered but unhealthy. Current and canary return ERROR_GENERATION_UNHEALTHY with no delivered IDs. The authority oracle remains [8,10]; the implementation does not silently route to A.

    Action: QUERY_PATH_UNHEALTHY. Make the active B query path unhealthy.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 2: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path unhealthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation B; I=24, C= 27. Status ERROR_GENERATION_UNHEALTHY; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status ERROR_GENERATION_UNHEALTHY; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status ERROR_GENERATION_UNHEALTHY; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  23. M22: Roll back to valid, healthy, maintained A

    The guarded rollback chooses healthy, valid, compatible, maintained A with C27. Both routes change together; the held reader keeps S22.

    Action: ROLLBACK_PUBLISHED. Roll back to valid, healthy, maintained A.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 3: defaultA, canary A. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path unhealthy. Shadow checked at 24; canary checked at 24 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status ERROR_GENERATION_UNHEALTHY; missing committed positions [].

    Actual delivered response: []; distances []. Unavailable on this path; delivers no IDs.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    Selected projections: []. Required artifacts: [].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  24. M23: Repair B and invalidate its exposure gates

    B becomes healthy and its prior exposure checks are invalidated. Repair alone does not authorize a new cutover.

    Action: REPAIRED_RECHECK_REQUIRED. Repair B and invalidate its exposure gates.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 3: defaultA, canary A. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  25. M24: Recheck B against exact state at 27

    The shadow gate is rerun at current boundary27, including doc10 and the retained doc7 deletion barrier.

    Action: SHADOW_PASSED. Recheck B against exact state at 27.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 3: defaultA, canary A. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at none .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  26. M25: Recheck B canary at 27

    The canary recheck at27 changes only the canary route toB while default staysA.

    Action: CANARY_PASSED. Recheck B canary at 27.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 4: defaultA, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-A, A-base-22, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  27. M26: Switch to B after current-boundary checks

    Checked B now becomes the default. Routing revision5 follows revision4 from canary publication.

    Action: CUTOVER_PUBLISHED. Switch to B after current-boundary checks.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 5: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=24; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24]; applied tail [26, 27]; active base B-base-24.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1].

    Current default route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=24, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-24, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  28. M27: Publish durable B checkpoint 27

    A durable valid B-base-27 checkpoint is published with the tombstone barrier. This adds the replacement-checkpoint prerequisite for A cleanup.

    Action: BASE_PUBLISHED. Publish durable B checkpoint 27.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 5: defaultB, canary B. Held reader pins A-base-22/S22; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=27; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24, 26, 27]; applied tail []; active base B-base-27.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].
    • B-base-27, cursor27: latest per-document record positions [22, 24, 26, 27].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1, B-base-27].

    Current default route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=22; generation A; I=22, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [7v1, 8v1]; distances [0.10, 0.20]. Exact paper answer at its selected S.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    • doc7 v1: live; position20; distance 0.10.
    • doc8 v1: live; position21; distance 0.20.
    • doc9 v1: live; position22; distance 0.20.

    Selected projections: [projection-7-v1, projection-8-v1]. Required artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1].

  29. M28: Release the A reader pinned at 22

    The held reader explicitly releases its A-base-22 reference. Rollback obligations remain open.

    Action: READER_RELEASED. Release the A reader pinned at 22.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 5: defaultB, canary B. Held reader released; rollback window open.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=27; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24, 26, 27]; applied tail []; active base B-base-27.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].
    • B-base-27, cursor27: latest per-document record positions [22, 24, 26, 27].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1, B-base-27].

    Current default route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=none; generation none; I=none, C= none. Status RELEASED; missing committed positions [].

    Actual delivered response: []; distances []. Reader released; no read requested.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    Selected projections: []. Required artifacts: [].

  30. M29: Explicitly close the A rollback window

    The rollback window is explicitly closed. A rollback is unavailable by declared scope after this point, even before files are reclaimed.

    Action: ROLLBACK_WINDOW_CLOSED. Explicitly close the A rollback window.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 5: defaultB, canary B. Held reader released; rollback window closed.

    Generation A: publication and coverage

    I=22; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at none; canary checked at none .

    Snapshot coverage [20, 21, 22]; applied tail [23, 24, 26, 27]; active base A-base-22.

    • A-base-22, cursor22: latest per-document record positions [20, 21, 22].

    Retained artifacts: [generation-A, A-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, projection-8-v2, projection-10-v1].

    Generation B: publication and coverage

    I=27; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24, 26, 27]; applied tail []; active base B-base-27.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].
    • B-base-27, cursor27: latest per-document record positions [22, 24, 26, 27].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1, B-base-27].

    Current default route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=none; generation none; I=none, C= none. Status RELEASED; missing committed positions [].

    Actual delivered response: []; distances []. Reader released; no read requested.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    Selected projections: []. Required artifacts: [].

  31. M30: Reclaim A after references and rollback obligations end

    No allowed reader or route references A, rollback is closed, and valid durable B checkpoint27 covers D27. A can be reclaimed. Authority, original receipts and the doc7 tombstone barrier remain. Rebuilding A later would be a separate protocol.

    Action: GENERATION_RECLAIMED. Reclaim A after references and rollback obligations end.

    D=27; B=22; committed [20, 21, 22, 23, 24, 26, 27]; written-only [25]. Routing revision 5: defaultB, canary B. Held reader released; rollback window closed.

    Generation A: publication and coverage

    I=none; C=none; reclaimed; backfill complete; worker closed; query path unhealthy. Shadow checked at none; canary checked at none .

    Snapshot coverage []; applied tail []; active base none.

    Retained artifacts: [].

    Generation B: publication and coverage

    I=27; C=27; valid; backfill complete; worker running; query path healthy. Shadow checked at 27; canary checked at 27 .

    Snapshot coverage [20, 21, 22, 23, 24, 26, 27]; applied tail []; active base B-base-27.

    • B-base-22, cursor22: latest per-document record positions [20, 21, 22].
    • B-base-24, cursor24: latest per-document record positions [21, 22, 24].
    • B-base-27, cursor27: latest per-document record positions [22, 24, 26, 27].

    Retained artifacts: [generation-B, B-base-22, projection-7-v1, projection-8-v1, projection-9-v1, projection-7-v2, B-base-24, projection-8-v2, projection-10-v1, B-base-27].

    Current default route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Canary route

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Direct candidate B diagnostic

    Selected S=27; generation B; I=27, C= 27. Status OK; missing committed positions [].

    Actual delivered response: [8v2, 10v1]; distances [0.03, 0.15]. Exact paper answer at its selected S.

    Required reference: [8v2, 10v1] at S=27. Full committed-history oracle at this selected current boundary.

    • doc7 v3: deleted; position24; distance none (deletion barrier).
    • doc8 v2: live; position26; distance 0.03.
    • doc9 v1: live; position22; distance 0.20.
    • doc10 v1: live; position27; distance 0.15.

    Selected projections: [projection-8-v2, projection-10-v1]. Required artifacts: [generation-B, B-base-27, projection-8-v2, projection-10-v1].

    Held historical reader

    Selected S=none; generation none; I=none, C= none. Status RELEASED; missing committed positions [].

    Actual delivered response: []; distances []. Reader released; no read requested.

    Required reference: [7v1, 8v1] at S=22. Independent manual S22 reference; it remains historical teaching context after release.

    Selected projections: []. Required artifacts: [].

Four checked unsafe branches

Unsafe cutover atM09

Guarded action: Reject target24: B misses committed delete24; defaultA remains correct.

Unsafe change: Forced stale B at S23 includes deleted7v2 and misses9 at required S24. Error boundary: ERROR_COVERAGE_GAP.

Forced stale diagnostic atS23: [7v2, 8v1] ; distances [0.05, 0.20]. Required current reference atS24: [8v1, 9v1] . This diagnostic is not delivered as a fresh response.

Unsafe rollback atM19

Guarded action: Reject target27: retained A misses committed27; defaultB remains correct.

Unsafe change: Forced stale A at S26 misses10 and includes9 outside exact top2 at required S27. Error boundary: ERROR_COVERAGE_GAP.

Forced stale diagnostic atS26: [8v2, 9v1] ; distances [0.03, 0.20]. Required current reference atS27: [8v2, 10v1] . This diagnostic is not delivered as a fresh response.

Premature reclaim atM15

Guarded action: Keep A: held reader pins A-base-22/S22 and rollback window is open.

Unsafe change: Removing A keeps current B correct, but held reader and immediate rollback have no generation. Error boundary: ERROR_MISSING_GENERATION.

Current default route after the unsafe change: status OK; actual delivered [8v1, 9v1]. Required reference [8v1, 9v1] atS 24; selectedS24; required artifacts [generation-B, B-base-24, projection-8-v1, projection-9-v1].

Held historical reader after the unsafe change: status ERROR_MISSING_GENERATION; actual delivered []. Required reference [7v1, 8v1] atS 22; selectedS22; required artifacts [].

Immediate rollback also returns ERROR_MISSING_GENERATION. Retained authority could support a separately designed rebuild; it does not provide this immediate rollback path or prove permanent data loss.

Missing pinned base atM15

Guarded action: Keep A-base-22 until its pinned reader releases.

Unsafe change: Removing only A-base-22 leaves the held reader without its compatible base. Error boundary: ERROR_MISSING_BASE.

Held historical reader after the unsafe change: status ERROR_MISSING_BASE; actual delivered []. Required reference [7v1, 8v1] atS 22; selectedS22; required artifacts [].

Independent changed input: later records with a delete hole

B uses I22 and snapshot coverage[20, 21, 22], then applies[23, 26, 27]. D27 does not commit25. C remains23, because committed24 is missing. Guarded target27 action and generation-only read return ERROR_COVERAGE_GAP, delivered IDs[].

Forcing the incomplete represented state atS27 gives[8v2, 7v2] at distances[0.03, 0.05]. It includes deleted7 and misses10. Required reference:[8v2, 10v1] atS27.

Minimal repair: replay committed24; C becomes27, and the delivered exact answer is[8v2, 10v1]. Written-only25 stays excluded. Exposure gates still need rechecking before a cutover.

Publish a checked destination, then publish its route

B’s query readiness needs more than an answer list. A valid base must represent the correct full per-document state, including tombstones; needed generation/base/projection artifacts must exist; the answer contract must match; the query path must be healthy; and its maintenance/read capability must work. C must cover every committed record through the intended target.

PostgreSQL18’s concurrent index construction gives a concrete comparison: it begins with an invalid catalog index, performs scans and waits, and later marks the index valid. Concurrent construction requires more work and can add CPU/I/O load. A failed invalid index can be ignored by queries while still imposing update overhead. Those are PostgreSQL’s rules; our finite readiness predicate is independently stipulated.

Before targetT cutover, this model requires:

  1. T still equals authorityD at the guarded routing action.
  2. B is valid, compatible, healthy and query-capable, with needed artifacts and complete committed coverage throughT.
  3. Shadow checks atT compare full winning-record state, exact IDs, versions, distances and projection keys. Matching two ANN lists would not prove completeness.
  4. The finite canary check at the sameT confirms the declared healthy, compatible, covered query path. Real service/relevance/resource gates still need measurements.
  5. The complete intended metadata route revision publishes successfully.

M12 passes the finite shadow check at24. M13 exposes/checks canaryB while default remainsA, publishing revision1. M14 injects a routing-write failure before metadata commit, with a known unchanged outcome: defaultA/canaryB and revision1 remain. M15 rechecks the target and gates, then publishes revision2 with defaultB/canaryB.

The check and metadata commit are serial in this synthetic schedule: authority cannot advance between them. A real service must supply a mechanism that satisfies that relationship. An ambiguous timeout requires its own inspect/resolve/retry contract before the intended committed revision is known.

Elasticsearch’s aliases documentation describes a multiple-action atomic swap example. The adjacent multiple-action results section also shows partial success: acknowledged:true appears with errors:true, and must_exist:true can make the entire list fail when an action fails. Inspect the documented complete success criteria; a top-level acknowledgement alone does not prove the intended route changed. Our known precommit failure does not describe every alias request or timeout.

Retained files must still support current rollback

After cutover we maintain both derived generations. AtM16 the writer commits26 and both reach C26;25 remains written-only. M17 stalls A maintenance. M18 commits insertion27, which only B applies. Current D=S27 expects [8v2,10v1]. A files are still retained, and its heldS22 reader still works, but A’s current coverage ends at26.

Check whether retained A is ready for rollback atM19

It is undercovered. A has I22/C26 and lacks committed27. Guarded rollback returns ERROR_COVERAGE_GAP, missing[27], preserving defaultB’s correctS27 answer [8v2,10v1].

Forcing A’s staleS26 state would give [8v2,9v1], distances0.03/0.20. Doc10 is missing, and9 is outside exact top2 at requiredS27. Retained A bytes establish neither current coverage nor a working maintenance path.

Resume A’s worker and replay27 atM20. A reaches C27 using I22 plus its complete applied tail. AtM21 B becomes unhealthy: its C27 does not prevent the current path returning ERROR_GENERATION_UNHEALTHY with no delivered IDs. There is no automatic route fallback. M22 separately checks and publishes rollback to healthy, compatible, maintained A at target27, revision3, returning [8v2,10v1].

A pass states current targetD, missing27, the wrong stale IDs/versions, working read/maintenance capability and the successful route revision. It keeps the heldS22 reference [7v1,8v1] separate throughout.

Rollback has a bounded window. Its target must still equalD; A must be valid, compatible, healthy and query-capable, with the needed artifacts, complete coverage through the current target and running maintenance. Retention is one requirement. The B exposure gates do not substitute for those A obligations.

M23 repairs B and invalidates its old gates. M24/M25 recheck shadow/canary at27, then M26 publishes revision5 toB. The intermediate canary update was revision4. Reusing a check at24 after authority has advanced to27 would leave the new state unexamined.

Close the window before reclaiming its state

M27 publishes a valid durable B-base-27 checkpoint, including doc7’s deletion barrier. M28 explicitly releases the old reader pinned to A-base-22/S22. M29 explicitly closes the A rollback window. AtM30 default/canary refer toB, no allowed A reader/reference remains, rollback is closed and B’s durable I27/C27 checkpoint covers D27. Only then does this schedule reclaim A.

Check premature cleanup while the old reader and rollback window remain open

Remove A atM15. CurrentB atS24 still returns [8v1,9v1]. The heldS22 path returns ERROR_MISSING_GENERATION, deliveredIDs[]; its historical required reference remains [7v1,8v1]. Immediate rollback also returns ERROR_MISSING_GENERATION.

If only A-base-22 is removed, the held reader returns ERROR_MISSING_BASE. A newer B base cannot silently replace its pinned generation/base/S. Retained authority might permit a separately designed rebuild; rebuilding is not this immediate rollback path, and the example makes no permanent-data-loss claim.

The last cleanup prerequisite becomes true when the rollback window closes atM29. Reclamation occurs next atM30. Authority, original receipt identities and B’s tombstone barrier remain retained. Closing the window intentionally ends immediate A rollback even before files disappear. A pass names both the pinned-reader and rollback obligations, the exact failure statuses, and the replacement checkpoint retained after cleanup.

Change one input: a later offset with an earlier hole

Use B’s snapshot22 and I22, then apply23,26 and27. Omit committed delete24. Authority remains D27;25 is still written-only. Predict C, the guarded target27 action, the forced incomplete result and the minimal repair.

Check the independent delete-hole variant and repair
caseapplied_positionsCmissing_committedstatusforced_incomplete_idsrequired_idsrepair
omit-delete[23,26,27]23[24]ERROR_COVERAGE_GAP[8,7][8,10]replay24
repaired[23,24,26,27]27[]OK-[8,10]-

C23 is the largest complete committed prefix, even though maximum applied position is27. The guarded query/cutover rejects target27 and delivers no IDs. Forcing the incomplete represented state atS27 would give [8v2,7v2], distances0.03/0.05: deleted7 survives and10 is missing. The required answer is [8v2,10v1].

Replay committed24. The v3 tombstone suppresses doc7v2, C reaches27 and the exact query returns [8v2,10v1]. Written-only25 remains excluded; it is never promoted to “repair” the hole. Restored coverage still requires the other exposure predicates before route publication.

A pass computes the prefix rather than the maximum, identifies the deletion barrier and wrong IDs/versions, and repairs the missing committed operation while preserving the selectedS and answer contract.

Choose the plan from operating constraints

The worked schedule uses coherent backfill plus replay, then dual maintenance during a rollback window. It has alternatives:

PlanAssumption that makes it usefulMain cost/failure boundaryCondition that reverses the preference
Backfill plus authoritative replayA coherent snapshot connects to retained committed changes, and replay can catch up.Build/replay and temporary artifacts; fuzzy scan, log loss, missing deletes or a growing replay deficit block cutover.Replay cannot close the deficit before retention/headroom runs out.
Dual derived maintenanceOne authority can feed both formats, and per-generation progress/failure is observable and recoverable.Each logical change creates work in both derived layouts; asymmetric failure and shared contention can separate visibility.Doubled maintenance exceeds the service’s resource budget. Two derived writes alone do not make an atomic authority transaction.
Constrained write/maintenance windowThe service permits a bounded pause/queue for writes with explicit acknowledgment and drain behavior.Write interruption and queued work; freeze the boundary or handle pending writes explicitly.The allowed write-availability/latency contract cannot absorb the window.

No option is universally cheapest. Define the workload and mandatory gates before examining candidate results. Pin corpus/contract/implementation versions, selected boundaries, arrivals, cache cohorts, updates and failure schedule. Compare A and B at matchedS against compatible exact or justified fidelity references; judged relevance and current-policy disclosure remain separate.

Measure migration overhead by phase. Logical mutations and derived KV key/value bytes are different from WAL/compaction/physical bytes. Track remote requests, dependent rounds and transferred bytes separately; record CPU/memory, queue age/service/deficit, failed/capped requests, read-stage/end-to-end distributions and write visibility by required tenant/query slices. A paired shadow run adds query work, so its latency is not exposed-user canary latency. Treat new-generation cold-cache behavior as a declared cohort rather than burying it in an aggregate.

For replay progress, count and age missing committed operations. Raw integer D−C is not the count when25 is written-only. Stall a worker under continuing arrivals, then measure whether its deficit shrinks after resumption. Stop/advance thresholds, retention margin and rollback-window duration must come from the service’s requirements; this fixture supplies no numeric performance gates or observations.

Leave a migration plan someone can falsify

Write a one-page plan with: the preserved answer/availability/freshness promise; authority and retry identity; coherent snapshot and retained replay boundary; version/delete resolution and complete-prefix coverage; exact/fidelity and health/exposure gates; routing success/unknown-outcome semantics; current-target rollback scope/capability/artifacts; released references, closed window and replacement checkpoint before cleanup.

Then supply one fault schedule that breaks it, the exact wrong result or unavailable status, and the smallest repair. Use missing delete24, retained-but-undercoveredA at27, or premature A cleanup as a starting point. Name which workload assumption would favor a different plan and the next measurement that could change that choice.

The completed artifact is a defensible migration decision under stated assumptions. A finite model or a successful browser interaction does not demonstrate production safety or a reader’s ability to transfer it to a new system.

Selected readings

  • Debezium PostgreSQL3.3 connector: read initial snapshot workflow, snapshot isolation configuration and crash/duplicate behavior together. They connect scan and stream boundaries while preserving configuration/recovery caveats.
  • PostgreSQL18 concurrent index construction: examine invalid/valid states, waits, extra scans/load and failed-build overhead. This is a concrete product protocol and resource comparison.
  • Elasticsearch aliases: read the atomic swap example alongside multiple-action partial results and must_exist. Successful intended routing needs the documented complete action outcome.

These selected passages were inspected on October1,2026. They support the stated comparisons, not this exact synthetic protocol or a proprietary vendor migration. Full book texts and real workload canary measurements are outside the evidence here.

Search-systems Ch 8/8
  1. 1 A Map of Search Systems 10m
  2. 2 When an Index Becomes Your Data Model 11m
  3. 3 Doing Less Work, and Doing Work Faster 15m
  4. 4 Finding Neighbors Inside the Eligible Corpus 15m
  5. 5 From Durable Write to Searchable Snapshot 15m
  6. 6 Paying for Retrieval Across Storage and Shards 18m
  7. 7 From Oracles to a Launch Decision 18m
  8. 8 Change a Live Index Without Changing Its Promises 16m