Add ADR 0012 amending ADR 0002 and ADR 0003: projection stages, provisional lifespan after 3 observed hours, short scenario horizons, evidence ladder, and TUI unverified TBW entry. Add Projection stage, Provisional projection, Evidence ladder and Activity readout to the glossary.
3.5 KiB
3.5 KiB
12. Staged projection with an evidence ladder
Status: Accepted. Amends ADR 0002 §2, §6, §8 and §11, and ADR 0003 §4 and §8 for the TUI baseline entry.
Context
Under ADR 0002 as implemented, a fresh install showed no usage-adjusted theoretical lifespan until a manual baseline existed and a complete local observation day had passed. Confidence then stayed Limited until two scenario horizons existed, about 28 days. Users read this as Fenris being slow and its confidence never moving. The architecture review of 2026-10-02 also found that the TUI and CLI each pre-gated the projection with rules the projection itself does not use.
Decision
- Projection stages. The projection reports one projection stage: no observations yet, provisional, warming, limited, supported, or unavailable. Provisional and warming add to ADR 0002's three confidence states, which remain the categorical judgement once warm-up ends. Callers render the stage. They never pre-gate.
- First number after 3 observed hours. A provisional projection appears once at least 3 hours of hour observations with samples exist. Until 24 hours are observed, it carries the fact "daily cycle not yet seen". From 24 hours until ADR 0002's 14-qualifying-day warm-up completes, the stage is warming. The complete-local-day condition is a contributing fact, not a gate. The rate formula is unchanged; only the evidence span is shorter.
- Short horizons. Until a 7-day horizon is covered, the scenario range uses 24-hour and 3-day horizons, each shown only once covered. They drop out when the 7-day horizon exists. The scenario range remains the only spread shown, and still no statistical interval appears.
- Horizon agreement over existing horizons. As ADR 0002 §8 already says, agreement is judged across the horizons that exist. A single 7-day horizon passes, so Supported is reachable at 14 qualifying days when every other condition holds.
- Evidence ladder. Each Supported condition from ADR 0002 §8 is reported as met or unmet with its reason. The headline shows a count of conditions met, and the outlook shows the full ladder. Confidence is never a percentage.
- Write rate without a baseline. When no endurance baseline applies, the sustained-regime write rate is shown in place of a lifespan. No baseline is synthesized.
- TUI baseline entry. The TUI offers an unverified-override entry: rated TBW plus an optional source URL. It is persisted through
fenris-monitor baseline setunder the existing polkit action. Verified overrides with full provenance stay CLI-only.
Considered options
- Numeric confidence percentage. Rejected: it implies precision the evidence cannot support, and ADR 0002 §8 already rejected it.
- Capacity-based default baseline. Rejected: ADR 0002 dropped
capacity × 600, and a fabricated baseline would mislabel the lifespan. - Keep the complete-local-day gate. Rejected: it delays the first number by up to 34 hours while adding nothing the provisional label and spread do not already disclose.
Consequences
- Early lifespans swing widely. The provisional label, the hours observed and the short-horizon spread carry that honestly.
- The projection module's interface becomes the single test surface for every gating rule.
- ADR 0002 §10's implied baseline still needs two Percentage Used increments. Entering a rated TBW remains the fast path to a lifespan.