design: format registry, structured-data profiles, document metadata and search (D133, D134) - #453
Conversation
…cument subject entities (D133, D134) D133 replaces the operator-built MIME route table with an engine-shipped format registry: each family gets a posture (full reading, profile of a data file without its rows, expansion of containers into child documents, or a deterministic file card), deployments overlay rather than replace it, and routing keys are normalized after byte detection (D132). Profiles add a `computed` evidence mode, queryable Parquet copies and a `data_query` primitive over DuckDB; four locator kinds point into structured sources. D134 lets a document be the subject of a claim: a lineage-bound document entity minted on first self-subject claim, reached through a per-document self card that binds without the resolution cascade. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Accept all 15 findings: concrete registry entries and detection precedence (refining D132's text-flavour rule), hard full-reading bounds, copy and disclosure rules for profiles, E1/E2 extraction-eligibility mechanism, process-isolated data_query with private query assets, the expand sub-worker with member records, collision-safe member keys, counting_lineage_id for D54, descendant-closure forget with member suppressions, and whole-tree bounds. D134 gains a citable DOCUMENT passage, the subject_is_document flag, a unique row-locked binding on documents.document_entity_id, document_metadata alias provenance, rename metadata observations and a forget scrub. Reconcile retrieval, schema, E0, E1, lifecycle and hard-forget designs and eval checks. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Codex review, round 1 (gpt-6-sol, high reasoning), on 591d7e6Codex's findings, verbatim:
Verdict: Not implementation-ready. The direction is coherent, but the registry’s deterministic routing, E2 filtering, SQL isolation, child lifecycle, document-entity identity, and several binding contracts remain unresolved. The current design corpus would lead independent implementers to incompatible behavior. How each finding was handledI accepted all 15 findings and rejected none. The changes are in 0a8bd9f. The table in the analysis (§9, |
Concrete registry MIME types and aliases; a separate private object store for query assets and staged members; block-aligned extraction eligibility validated at conversion; a mandatory no-network sandbox for data_query with separate input and scratch directories and its own DataQueryResult/v1; immutable parent listings with member handles and mutable member records; position-free member keys; counting_lineage_id in the open-query projection; forget manifest v2 with per-descendant entries and member suppressions. D134 binds only the subject position of claims Claimify marks document_is_subject, and tracks document_metadata aliases per contributing document. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Codex review, round 2 (gpt-6-sol, high reasoning), on 0a8bd9fCodex's findings, verbatim: A. Round-1 findings
B. Problems exposed by the revision
VerdictNot implementation-ready. The revision resolves several round-1 issues, but private data remains exposed by the mount contract, and the new E1, expansion, query-result, document-subject and forget mechanisms still give implementers conflicting instructions. No files were changed. How each finding was handledI accepted all of them and rejected none. The changes are in 685c6c3. The Round 2 table in the analysis (§9) maps each finding to its fix. Round 3, a check that each finding is resolved, is running now. |
Fixed-form member keys (content-hash-qualified for archive members and attachments, native IDs for exports), per-source alias spellings with the displayed alias rebuilt from survivors, no mutable member reasons in the parent's immutable coverage, a registry-wide alias table, and a content-free alias section in forget manifest v2. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Codex review, round 3 (gpt-6-sol, high reasoning), on 685c6c3Codex's findings, verbatim: A. Round-2 verification
B. New must-fix problems introduced by the revision
VerdictNot implementation-ready. The revision resolves most round-2 contract conflicts, but member identity can still change across versions, alias forget can retain source-exclusive text, and parent coverage still has conflicting immutable and mutable instructions. The registry also remains incomplete against its binding decision. This was a read-only review; the working tree is clean. How each finding was handledI accepted and fixed all of them in c1877dd. I also made one change of my own: the version-2 forget manifest listed alias names, and the manifest is supposed to hold no content, so it now lists entity IDs only. A narrow round 4 is checking these fixes. |
Registry text names one alias table; suppressions and forget manifest v2 store member-key hashes, never keys; §5.3 states that only message-export conversations gain child versions. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Codex review, round 4 (on c1877dd) and round 5 (on c28456e)Round 4, verbatim
NEW must-fix introduced by this commit: The new hash-qualified archive and attachment keys make an edit a new lineage, but §5.3 still says a changed member becomes a new version of the child. Both cannot be implemented as written. format_conversion_design.md, format_conversion_design.md. Verdict: D133/D134 are not implementation-ready. Round 5, verbatim
New must-fix problems introduced by this commit: None. Verdict: The D133/D134 design set is implementation-ready at the must-fix level across |
…, implementation and tests D133 now states that it binds the framework only. The family table is the target coverage; each family ships one at a time after a dedicated family design (required contents listed), its implementation and its own test suite. Unshipped families are recognized, stored and parked. The delivery plan lists foundations and every family as separate units. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…d document search (D134) D134 now binds general document metadata shared by every format family (authors, recipients, dates, title, file name, thread), search_documents, document filters on search, Claimify naming the document in self-references, and an E3 rule that a document's own name is never an entity. The document entity design moves to plan/proposals with its adoption trigger, and its schema, identity and forget reconciliation is reverted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Remove the D18-era document entity bridge; drop the extra search sidecar in favour of name indexes on document_metadata plus chunk_search grouped by document; define version semantics, as-of-pinned paging and live-only reads for search_documents; test reused claims per occurrence; mark self-references explicitly (names_own_document) so the own-name rule never suppresses an unrelated entity; separate the metadata mapping version. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Record every observed name in document_names (BM25 and trigram indexed) so same-byte renames are searchable; add the file name to the extraction reuse key; replace the claim-level self-reference flag with the exact span of the inserted name, skipping only that one reference and nothing when ambiguous. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…embers are temporary A container's immutable original holds every member, so hard forget of a single member is refused with a typed error naming the root; normal deletion of a member still suppresses it in later expansions. Staged member copies are deleted once each member is ingested, skipped or failed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…ix leftovers Hard forget of a container also blocks re-ingesting its members under D74's permanent guard; the design now says so instead of suggesting re-ingestion. Remaining text that described per-member hard forget is aligned with the typed refusal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…eference gate
Add the card formats (DWG, fonts, disk images, executables, DXF) and the
line-shaped message-export grammar to the detection order. The
self-reference gate now rejects only when the whole inserted name is already
in the source span, so a shared word ("report" in "Annual Report") keeps the
marker.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…ct tests Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
D134 replaced: document metadata and search, reviewed by Codex (gpt-6-sol, high reasoning)At the owner's direction (2026-09-24), D134 no longer makes documents entities. That design moved to
Review: d134Must-fix
Should-fix
Verdict: Not implementation-ready at the must-fix level. Review: d134bPrevious review
New must-fix problems in D134
Verdict: The D133/D134 set is not implementation-ready at the must-fix level. Review: d134cD134 follow-up (
New must-fix problems (
Verdict: No — D133/D134 is not yet implementation-ready at the must-fix level. Review: d134d
New must-fix: Forgetting one container member only records a suppression against future expansion (format_conversion_design.md:516). The surviving parent still retains its mounted raw container, which contains that member’s bytes (e0_files_design.md:48); member bytes are also staged under the parent’s private-store path (format_conversion_design.md:420). The design needs an erasure rule for those parent-held copies to satisfy hard forget’s no-surviving-unique-content contract (hard_forget_design.md:22). Verdict: No—the D133/D134 set is not implementation-ready at the must-fix level. Review: d134eRESOLVED — format_conversion_design.md now refuses hard-forget of an individual member and requires forgetting the root container and its descendant closure. It also requires staged member copies to be removed after expansion, with interrupted copies included in the root’s forget inventory (line 527). New must-fix problems in
Verdict: The D133/D134 set is not implementation-ready at the must-fix level. Review: d134f
New must-fix problem: D133 collapses byte-identical embedded images into one member and requires every occurrence’s locator, but Verdict: The D133/D134 set is not yet implementation-ready at the must-fix level. Review: d134gRESOLVED. New must-fix problems in
Verdict: the D133/D134 set is not implementation-ready at the must-fix level. Review: d134hEarlier findings
New must-fix problems in
Verdict: No—the D133/D134 set is not implementation-ready at the must-fix level. Review: d134i
New framework-level must-fix problems across Verdict: Yes—the D133/D134 framework set is implementation-ready at the must-fix level. |
Delete and hard forget act on the uploaded document and cover every member expanded from it; members are never deleted or forgotten on their own. Drop member suppressions, the manifest v2 restructuring and the per-member refusal machinery; the forget manifest only gains member_doc_ids and the members' hashes and prefixes in its existing lists. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Keep D133/D134 before D135/D136, list data_query and search_documents in the D136 MCP catalogue sentence, and note that D135 deletion covers container members. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
… is a separate cleanup Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…st time Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
…stays the origin Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc
Summary
Design-only change: how the engine should accept and process every file format family. Adds two decisions.
D133 — one format registry (
plan/designs/format_conversion_design.md)Replaces the operator-built, exact-match MIME route table (two entries by default; configuring one route replaces the rest) with an engine-shipped format registry. Each family gets detection, canonical MIME types and aliases, a posture, a converter, provider requirements, a size limit, a cost-class label and a storage class. Deployments overlay the registry and never replace it. Routing keys are normalized after byte detection (D132, PR Detect ingest content class and label every object write #452).
Four postures:
evidence_modegainscomputed. E2 doesn't extract claims from profile structure ranges; those stay searchable.Profiled tables are stored as Parquet. A new
data_queryprimitive runs read-only SQL over them in an isolated DuckDB instance.New locator kinds:
sheet_range,table_region,json_pointer,line_range.Delivery: one family at a time. D133 binds the framework only; the family table is the target coverage. Each family ships only after three things are merged: its own family design (
plan/designs/formats/<family>_design.md, required contents in §10.1), its implementation, and its own test suite (fixtures, detection, golden rendering, source map, failures, end-to-end retrieval, performance). Until then, uploads of that family are stored and parked.plan/plans/format_coverage_delivery.mdlists the foundations and every family as separate units.D134 — document metadata and document search (
plan/designs/document_metadata_and_search_design.md)file_name,source_path,title,authors,recipients(each a name plus an address or handle),created_at,modified_at,language,thread_refandfamily. Each format family maps its own fields onto these; for example, an email's From becomesauthors. Every name a version has been seen under is recorded indocument_names, so renamed files can still be found.search_documentson the API, SDK, CLI and MCP. It finds documents by name, metadata and content, reusing the existing chunk search rather than adding a new index. Results include each document's metadata and the handles to open it. If a name matches several people, all of them are listed.search. Filters can be applied to chunks, claims and facts. Claims are checked per occurrence, so a claim reused in a later version is tested against that version. Filters are applied before the top results are cut, so filtered searches don't lose results. For example: "everything about Project X from emails from Alice".documents.document_entity_idcolumn, which linked a document to an entity, is removed.plan/proposals/document_subject_entities.md.Supporting documents: the analysis (
plan/analysis/format_coverage_and_conversion_architecture.md) and the delivery order (plan/plans/format_coverage_delivery.md). E0 §3, the media locator schema and evidence-mode table, entity identity §5, the D122 design andplan/README.mdare reconciled with the new decisions. Refinement notes were added inside D38, D65, D96, D117 and D122.Numbering: D133 and D134 follow D132, which is proposed in PR #452. This PR depends on D132 for byte detection and requires D132's detection classes to be extended; see design §2.
Verification
Contributor agreement
Signing on behalf of a legal entity (leave blank if accepting individually):
🤖 Generated with Claude Code
https://claude.ai/code/session_01E9rdAXzioTMsGYqpJn44zc