Define endurance-baseline provenance and validation #12

Closed
opened 2026-08-31 10:09:48 +00:00 by xavierk · 1 comment
Owner

Parent map: Chart Fenris’s persistent TUI monitoring redesign

Question

Which provenance fields are mandatory for a rated-TBW override beyond ADR 0001's source URL, document revision, and entry date — model, capacity, region? How is an unverified manual override flagged, and what validation against the detected drive (model and capacity match) must the CLI perform before accepting or retaining an override? May amend ADR 0001 if the field set changes.

Parent map: [Chart Fenris’s persistent TUI monitoring redesign](https://git.bongbetic.com/xavierk/Fenris/issues/1) ## Question Which provenance fields are mandatory for a rated-TBW override beyond [ADR 0001](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/adr/0001-observation-store-sqlite.md)'s source URL, document revision, and entry date — model, capacity, region? How is an unverified manual override flagged, and what validation against the detected drive (model and capacity match) must the CLI perform before accepting or retaining an override? May amend ADR 0001 if the field set changes.
xavierk added this to the Wayfinder: Fenris persistent TUI monitoring redesign milestone 2026-08-31 10:09:48 +00:00
xavierk added the wayfinder:grilling label 2026-08-31 10:09:48 +00:00
xavierk added a new dependency 2026-08-31 11:45:44 +00:00
xavierk self-assigned this 2026-08-31 15:18:52 +00:00
Author
Owner

Resolution

Settled over two grilling rounds; all recommendations accepted as proposed.

Provenance field set. Mandatory: source URL, document revision, entry date (ADR 0001), model string, and nominal capacity — the two fields datasheet TBW is keyed by. No region field (TBW ratings are global; only warranty terms vary, already carried by the disclosure language) and no separate manufacturer (redundant with the model string). The value is entered as decimal TBW and stored as bytes (E_rated = entered_TBW × 10¹², per ADR 0002).

Cardinality and state. One active row, replaced on edit; no audit trail. Verification is derived at read, never a stored boolean: verified ⇔ provenance complete and validated against the detected drive, where validation is a machine match or a recorded user attestation. The row freezes its validation facts: detected model, detected capacity bytes, validated_by (machine/user), validated_at.

Unverified tier. Entry refuses incomplete provenance by default; storing without it requires an explicit unverified acknowledgment, which records missing fields as NULL. Such a row is ADR 0002's tier-2 baseline, labeled "user-supplied, unverified". Without a TTY, a model-mismatch confirm likewise refuses with instructions — refusal is the default everywhere except where a human explicitly acknowledges.

Entry-time validation (unprivileged). The CLI reads the configured drive live from world-readable sysfs (/sys/class/nvme/<dev>/model, block-device size) — no helper, no library. This is two plain file reads, not a collector acquisition path, so Choose the collector's NVMe acquisition path is unaffected. Model match: case-insensitive, whitespace-collapsed containment in either direction; a mismatch prompts an interactive confirm, and confirming records validated_by = user. Capacity match: entered nominal capacity within ±1% of detected namespace bytes.

Retention and read-time applicability. Never auto-delete. At projection time, applicability is a model match against the current controller segment's mn (normalized per the controller-identity decision); capacity is an entry-time fact only. A mismatch means "no applicable baseline" → projection Unavailable with contributing fact "baseline does not match current drive"; status shows the mismatch.

Write path and CLI surface. fenris baseline set | show | clear. show reads the observation store directly; set and clear persist through the polkit-guarded helper's new baseline verb — validation logic stays in unprivileged CLI code, mirroring ADR 0003's sanctioned-toggle pattern.

Artifacts. ADR 0001 and ADR 0003 amended in place with Status notes; CONTEXT.md gains Verified override / Unverified override and a precedence-accurate Endurance baseline entry — 4d332be.

Map impact. No new tickets, no fog graduated: the assembly item stays put until the remaining decisions close. Decide controller-segment metadata columns is untouched (no capacity column anywhere); the acquisition-path ticket is unaffected as noted above.

## Resolution Settled over two grilling rounds; all recommendations accepted as proposed. **Provenance field set.** Mandatory: source URL, document revision, entry date (ADR 0001), **model string**, and **nominal capacity** — the two fields datasheet TBW is keyed by. No region field (TBW ratings are global; only warranty terms vary, already carried by the disclosure language) and no separate manufacturer (redundant with the model string). The value is entered as decimal TBW and stored as bytes (`E_rated = entered_TBW × 10¹²`, per ADR 0002). **Cardinality and state.** One active row, replaced on edit; no audit trail. Verification is **derived at read, never a stored boolean**: verified ⇔ provenance complete **and** validated against the detected drive, where validation is a machine match or a recorded user attestation. The row freezes its validation facts: detected model, detected capacity bytes, `validated_by` (`machine`/`user`), `validated_at`. **Unverified tier.** Entry refuses incomplete provenance by default; storing without it requires an explicit unverified acknowledgment, which records missing fields as NULL. Such a row is ADR 0002's tier-2 baseline, labeled "user-supplied, unverified". Without a TTY, a model-mismatch confirm likewise refuses with instructions — refusal is the default everywhere except where a human explicitly acknowledges. **Entry-time validation (unprivileged).** The CLI reads the configured drive live from world-readable sysfs (`/sys/class/nvme/<dev>/model`, block-device size) — no helper, no library. This is two plain file reads, not a collector acquisition path, so [Choose the collector's NVMe acquisition path](https://git.bongbetic.com/xavierk/Fenris/issues/16) is unaffected. Model match: case-insensitive, whitespace-collapsed containment in either direction; a mismatch prompts an interactive confirm, and confirming records `validated_by = user`. Capacity match: entered nominal capacity within ±1% of detected namespace bytes. **Retention and read-time applicability.** Never auto-delete. At projection time, applicability is a model match against the current controller segment's `mn` (normalized per the controller-identity decision); capacity is an entry-time fact only. A mismatch means "no applicable baseline" → projection Unavailable with contributing fact "baseline does not match current drive"; `status` shows the mismatch. **Write path and CLI surface.** `fenris baseline set | show | clear`. `show` reads the observation store directly; `set` and `clear` persist through the polkit-guarded helper's new `baseline` verb — validation logic stays in unprivileged CLI code, mirroring ADR 0003's sanctioned-toggle pattern. **Artifacts.** [ADR 0001](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/adr/0001-observation-store-sqlite.md) and [ADR 0003](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/adr/0003-service-lifecycle-and-sanctioned-toggle.md) amended in place with Status notes; `CONTEXT.md` gains *Verified override* / *Unverified override* and a precedence-accurate *Endurance baseline* entry — [4d332be](https://git.bongbetic.com/xavierk/Fenris/commit/4d332be). **Map impact.** No new tickets, no fog graduated: the assembly item stays put until the remaining decisions close. [Decide controller-segment metadata columns](https://git.bongbetic.com/xavierk/Fenris/issues/14) is untouched (no capacity column anywhere); the acquisition-path ticket is unaffected as noted above.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#12