SOW v0.1 Decision Ledger: What Survived and What Was Retired
The v0.1.0 tag contains 44 ADR files numbered 0001 through 0045; 0006 is absent. This page preserves their meaning without republishing each historical implementation contract as current guidance.
An ADR is valuable even when its implementation is retired. It records the failure mode the team refused to ignore, the boundary selected at the time, and often the evidence required before a dangerous operation could proceed.
The table below classifies each decision into four fates:
| Fate | Meaning |
|---|---|
| Retained | The principle remains part of current SOW with substantially the same boundary. |
| Evolved | The problem and safety rule survived, but ownership or implementation changed. |
| Migration history | The decision governed a one-time Pigsty/V1 cutover and is no longer a product contract. |
| Retired | The decision belonged to the Git/CAS/Route/Edge product model removed from current SOW. |
Primary decision dates run from 2026-07-11 through 2026-07-28; ADR-0035 carries later amendments on July 29 and July 31. Most early ADRs were consolidated into Git on July 19 after already being used by implementation and evidence work. The v0.1.0 tag tree was checked to contain the same 44 ADR paths represented below. One raw link is intentionally omitted because the historical record names obsolete infrastructure details.
Core state, publication, and trust
| ADR | Original decision | Later fate |
|---|---|---|
| 0001 | Git was canonical state, SHA-256 CAS owned package bytes, refs expressed views/history, and publication used target sagas. | Evolved. Git/CAS/Route ownership retired; single ownership, pointer-last publication, independent target state, and evidence gates survived. |
| 0002 | Public routes, immutable generations, and client/provider compatibility had separate acceptance gates. | Evolved. Route machinery retired; protocol/client/provider evidence remains separate. |
| 0003 | Snapshots required verified generation copies and inventory-bound retention. | Evolved. CopyObject snapshot trees retired; retained generations now store metadata and reference sets without payload copies. |
| 0004 | Edge token verification and deployment had one versioned cross-provider contract. | Retired. Edge entitlement is no longer part of the SOW repository engine. |
| 0005 | Every legacy Make target was mapped to SOW, retirement, or policy rejection. | Migration history. The mapping completed its cutover role and left the active product. |
| 0007 | Public and gated packages shared one canonical repository instead of a separate Pro bucket. | Retired. The commercial Edge topology left product scope; the more general single-owner lesson remains. |
| 0008 | GC followed complete reachability and required explicit confirmation for destructive work. | Retained. Current local and target GC still require closure, exact identity, grace, and capability. |
| 0009 | Once a remote generation became visible, recovery rolled forward rather than inventing rollback. | Retained. Commit intent remains the boundary between abandon/reconcile and forward-only recovery. |
| 0010 | Metadata signing bound exact public/private identities and treated rotation as a repository-wide transition. | Evolved. Current signer evidence and trust-ring rules preserve exact identity without the V1 ref topology. |
| 0011 | Remote deletion required target ownership, inventory, checkpoint, grace, and conditional-delete evidence. | Retained. R2 remains report-only because it cannot satisfy the required atomic delete capability. |
| 0012 | Private origins, cache topology, and exact purge mapping were explicit deployment contracts. | Retired. CDN/private-origin deployment is outside current SOW. |
| 0013 | A persisted plan was recovery input to revalidate, never authority to replay blindly. | Retained. Managed recovery still rebinds plans, files, target identity, and public evidence. |
| 0014 | RPM provenance recorded exact packet evidence and distinguished ingestion policy from historical proof. | Evolved. Current package authentication and independent trust rings replace the V1 receipt encoding. |
| 0015 | Configuration named a target; published refs and checkpoints belonged to canonical state. | Retained. Target-neutral generations and target-prefix attempts/checkpoints remain separate owners. |
| 0016 | Cloud adapters used concrete, bounded SDK/API contracts instead of a generic provider abstraction. | Evolved. Concrete provider boundaries survived; V1 Edge/COS details retired. |
| 0017 | Accepted RPM signatures had to close against a stable repository keyring and opened payload identity. | Evolved. v0.4 independent multi-ring verification strengthens the same trust boundary. |
| 0018 | A selected package set staged, validated, committed, and recovered as one bounded local transaction. | Evolved. V1 materialization retired; current Plain/Managed pointer-last staging keeps the transactional lesson. |
Legacy topology, compatibility, and migration
| ADR | Original decision | Later fate |
|---|---|---|
| 0019 | EL7 metadata format and compressor behavior were frozen for legacy consumers. | Migration history. Current compatibility documentation, not this freeze, defines supported platforms. |
| 0020 | Every legacy physical path and selector group received an explicit owner. | Migration history. It prevented ambiguous cutover but is not a current repository model. |
| 0021 | Cross-EL yum/infra/{arch} projections were reproduced with exact frozen evidence. |
Migration history. The special projection left active product scope. |
| 0022 | Package history could not be broken merely because physical ownership moved. | Evolved. Generations, retained references, and migration journals now preserve continuity without V1 routes. |
| 0023 | Canonical Git objects were rebound to exact bytes before admission and use. | Evolved. Git authority retired; descriptor/path/digest identity checks remain. |
| 0024 | Materialized route receipts acted as narrow read/retirement capabilities. | Evolved. Route receipts retired; capability-bound inspection and deletion survived. |
| 0025 | Locks bound an exact process instance and stable lock inode rather than elapsed time. | Evolved. Stable lock inodes and rejection of timeout-based lock stealing survived; the V1 process-instance lease mechanism did not. |
| 0026 | Offline archive creation used a durable intent and strict archive admission. | Retired. Offline archive projection left current SOW scope. |
| 0027 | Legacy bytes entered canonical state only after exact path, package, and provenance admission. | Migration history. The adoption program completed; strict package admission remains in narrower form. |
| 0028 | DEB inspection opened only the control archive needed for metadata and rejected ambiguous containers. | Retained. Narrow parsing and bounded input remain part of the APT package boundary. |
| 0029 | Client floors and the EL8 freeze were explicit owner policy, not inferred from code. | Migration history. Current platform policy lives in the compatibility reference and release notes. |
| 0030 | Missing legacy YUM bodies could be repaired only from a reviewed blocker-set digest. | Migration history. The narrow negative-provenance exception did not become a general ignore flag. |
| 0031 | Gated legacy content required exact checksum repair and activation evidence. | Retired. Pro activation left product scope; fail-closed repair remained a general lesson. |
Provider and Edge control plane
| ADR | Original decision | Later fate |
|---|---|---|
| 0032 | Only one exact owner-designated Cloudflare test tuple could bypass normal production rejection. | Retired. It was a narrow historical test exception, never a general deployment rule. |
| 0033 | Read-only provider readiness had its own registry and ownership evidence. | Retired. Provider bootstrap registry left current SOW. |
| 0034 | Worker bootstrap used leases, two-phase recovery, exact resources, and reversible state. | Retired. Cloudflare deployment is no longer repository-engine responsibility. |
| 0035 | Provider identity, runtime bindings, log sink, and lease ownership were attested before use. | Retired. The exact Edge control plane left product scope. |
| 0036 | R2 lacked conditional DeleteObject, so an explicit checkpoint-fenced unconditional-delete fallback was allowed behind a deterministic capability probe and repeated identity/fence proofs. |
Evolved; fallback not inherited. Capability probing and fail-closed defaults survived, but current SOW disables R2 remote deletion and keeps target GC report-only. |
| 0037 | Gated publication had to prove denial at the Edge before uploading confidential bytes. | Evolved. The Edge product surface retired; proving authorization before exposure survived. |
| 0038 | YUM cutover required an expiring receipt bound to exact endpoints, generation, and trust bytes. | Migration history. It made a dangerous consumer cutover auditable and then retired. |
| 0039 | Caret had one canonical URL spelling across Go, Edge, logs, and origin routing. | Evolved. The route was retired; canonical encode-once path handling remains. |
Bounded configuration and derived-state recovery
| ADR | Original decision | Later fate |
|---|---|---|
| 0040 | Configuration cardinality and expanded topology were bounded before allocation or execution. | Retained. Current parsers and state wires keep explicit size/cardinality limits. |
| 0041 | Unknown final projection stages were preserved for audit rather than guessed away. | Evolved. Current recovery still preserves contradictory evidence and fails closed. |
| 0042 | Derived-state replacement had explicit success, rollback, preserved, and blocked outcomes. | Retained. Current operations report precise recovery outcomes instead of collapsing them into success/failure. |
| 0043 | File mutation bound descriptor identity and stated the same-UID hostile-writer limit honestly. | Retained. Path safety still fails closed without claiming protection outside its OS ownership boundary. |
| 0044 | Preserved audit copies could be retired only through an exact capability and confirmation token. | Evolved. The V1 command retired; exact capability-bound deletion remains a design rule. |
| 0045 | Unjournaled residue had a bounded classifier and could never be silently adopted or deleted. | Retained. Current recovery distinguishes known state, safe residue, and contradictory evidence. |
The pattern behind the ledger
The decisions that survived were not the most elaborate V1 mechanisms. They were the small invariants beneath them:
- one owner for each fact;
- exact identity before mutation;
- immutable preparation before pointer commit;
- forward recovery after commit intent;
- complete evidence before deletion;
- explicit bounds and honest non-goals;
- compatibility claims attached to the client/provider actually tested.
The Git database, route graph, Edge bootstrap, and migration commands were replaceable. These invariants were not. They are maintained today in Design Principles, System Model, and Publication & Recovery.
The v0.1.0 ADR directory remains the immutable primary source. The next article summarizes the separate v0.1 evidence record.