Define endurance-baseline provenance and validation #12
Notifications
Due Date
No due date set.
Blocks
#13 Define cross-cutting acceptance criteria
xavierk/Fenris
Reference: xavierk/Fenris#12
Reference in New Issue
Block a user
Parent map: Chart Fenris’s persistent TUI monitoring redesign
Question
Which provenance fields are mandatory for a rated-TBW override beyond ADR 0001's source URL, document revision, and entry date — model, capacity, region? How is an unverified manual override flagged, and what validation against the detected drive (model and capacity match) must the CLI perform before accepting or retaining an override? May amend ADR 0001 if the field set changes.
Resolution
Settled over two grilling rounds; all recommendations accepted as proposed.
Provenance field set. Mandatory: source URL, document revision, entry date (ADR 0001), model string, and nominal capacity — the two fields datasheet TBW is keyed by. No region field (TBW ratings are global; only warranty terms vary, already carried by the disclosure language) and no separate manufacturer (redundant with the model string). The value is entered as decimal TBW and stored as bytes (
E_rated = entered_TBW × 10¹², per ADR 0002).Cardinality and state. One active row, replaced on edit; no audit trail. Verification is derived at read, never a stored boolean: verified ⇔ provenance complete and validated against the detected drive, where validation is a machine match or a recorded user attestation. The row freezes its validation facts: detected model, detected capacity bytes,
validated_by(machine/user),validated_at.Unverified tier. Entry refuses incomplete provenance by default; storing without it requires an explicit unverified acknowledgment, which records missing fields as NULL. Such a row is ADR 0002's tier-2 baseline, labeled "user-supplied, unverified". Without a TTY, a model-mismatch confirm likewise refuses with instructions — refusal is the default everywhere except where a human explicitly acknowledges.
Entry-time validation (unprivileged). The CLI reads the configured drive live from world-readable sysfs (
/sys/class/nvme/<dev>/model, block-device size) — no helper, no library. This is two plain file reads, not a collector acquisition path, so Choose the collector's NVMe acquisition path is unaffected. Model match: case-insensitive, whitespace-collapsed containment in either direction; a mismatch prompts an interactive confirm, and confirming recordsvalidated_by = user. Capacity match: entered nominal capacity within ±1% of detected namespace bytes.Retention and read-time applicability. Never auto-delete. At projection time, applicability is a model match against the current controller segment's
mn(normalized per the controller-identity decision); capacity is an entry-time fact only. A mismatch means "no applicable baseline" → projection Unavailable with contributing fact "baseline does not match current drive";statusshows the mismatch.Write path and CLI surface.
fenris baseline set | show | clear.showreads the observation store directly;setandclearpersist through the polkit-guarded helper's newbaselineverb — validation logic stays in unprivileged CLI code, mirroring ADR 0003's sanctioned-toggle pattern.Artifacts. ADR 0001 and ADR 0003 amended in place with Status notes;
CONTEXT.mdgains Verified override / Unverified override and a precedence-accurate Endurance baseline entry — 4d332be.Map impact. No new tickets, no fog graduated: the assembly item stays put until the remaining decisions close. Decide controller-segment metadata columns is untouched (no capacity column anywhere); the acquisition-path ticket is unaffected as noted above.