Add a fail-closed FTS5 candidate audit - #2
Merged
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
This PR adds RecallLedger's first bounded FTS5 conformance layer without changing the durable schema or the serving search path.
Fts5CandidateAuditresult andSQLiteLedger.audit_fts5_candidatesascii,detail=none, andcolumnsize=0Verification
Final PR head:
3049a2dc1b2c0de1a5e2935944048a02feb18531.9039127989: 523,155 bytes, archive digestsha256:5eef3ccf5821c5fc1722d17e6f59391b00764d975d26cad5134150044373abd61592002185, 0 results across 50 security-extended rulesEvidence provenance
The adopted media remains bound to source commit
9ab4115e817deab4c843aa4d1680ef1cd63a9503and treebbc8dcc4d4e3f8456b469382902edd731e36ee56. Hosted artifact9038918220was independently reviewed before adoption; its API and recomputed archive digest are bothsha256:bb6c2f45693392a4febb252c22856e81ec097d429e7a8378eed1474dc844878d.All committed captures use normalized synthetic fixtures. The repository checks exact payload hashes, media structure, source inputs, privacy boundaries, and reproducibility. No secret, personal note, host path, or personal identifier is used as evidence.
Evidence boundary and non-claims
The installed-wheel PNG/GIF/SVG bundle proves the real packaged CLI workflow and general ledger behavior; it is not presented as direct FTS5 candidate-audit execution proof. The FTS5 diagram is a source-derived architecture explanation, not a photographed production system.
This is an ephemeral conformance/rebuild audit. It is not a persistent index, latency benchmark, serving-speed claim, semantic search system, embedding pipeline, authorization layer, production deployment, or user interface.
search_notesremains the correctness oracle and serving path.