Repository navigation
docs: describe the system as built with ADR-007, ADR-008 and ADR-009 - #216
Merged
paddymul merged 13 commits intoSep 26, 2026
Merged
Conversation
This was referenced Sep 22, 2026
paddymul
added a commit
that referenced
this pull request
Sep 24, 2026
…eps it (#195, #196) An unfaithful heal (a heal whose rows differ from the recorded digest) was pinned only by its record in errors.jsonl, which the error banner's dismiss deletes, so a dismiss unpinned the file (#196). _verify_self_heal now records the digest the heal wrote in the manifest, as unfaithful_heal_digest, and pinned_reason reads manifests only. The errors.jsonl record is still written, for the banner. A source version's heal (materialize._heal_a_source) goes through the same _verify_self_heal, so it gets the same pin. This is the first manifest field written after create; the recipe zip is written once, at the first checkpoint, so its copy of the manifest does not follow it. A reset back leaves a retired entry's snapshot on disk (ADR-007 D14, a reset leaves compute_cache/ alone) and parks the entry's dir in the bullpen, and the Cache page listed that file as an unpinned orphan and deleted it (#195). snapshot_manifest returns the live entry's manifest, or else the parked one, and the same pin rules apply to either. The listing marks such a row retired and fills it from the parked manifest; orphan now means a file no entry names, live or parked. The Cache page labels the row "(retired by a reset)" and does not link its hash. New with the port onto ADR-011: a source version is pinned when the clone of its imported bytes is gone from data/.cas. A reset back to a step before the import parks that clone in bullpen/cas beside the entry's dir, and a reset forward copies both back, so for a retired source version pinned_reason_of also accepts the parked clone (catalog_state.parked_clone_path). Without it every retired source version would be listed as pinned, with a reason saying its clone was gone. pinned_reason_of takes the project, the hash and whether the manifest is the parked one, since the source rule needs all three. The listing takes the pin from the manifest it already read, so it no longer parses errors.jsonl at all, where it used to parse the whole log once per row. Docs: ADR-007's implementation note on pinned files. docs/ is left to the rebase of #216. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
paddymul
added a commit
that referenced
this pull request
Sep 24, 2026
…hash Ported from #213 (61442dc, 537daee) onto the ADR-011 stack. The build's failure handler unlinked the entry's snapshot path whenever it had created the entry directory, without checking who wrote the file. A reset back leaves a parked entry's snapshot on disk (ADR-007 D14), and a build killed before its manifest leaves a half-built entry whose snapshot is still served, so a create of either that failed deleted a file it never wrote. For an entry that is not reproducible that file is the only copy of its rows (#193). A create now stages its snapshot. materialize(..., publish=False) leaves the file complete at its temp name, and the build moves it into place with publish_snapshot as its last step, after write_manifest. A build that fails before then removes only its temp file. A heal publishes at once, as before. A source entry's mint (ADR-011) needs no staging: _mint keeps a snapshot already at the path, since the entry hash fixes its rows, and its failure handler never touches the snapshot. A heal writes only when the file is absent. test_a_failed_re_import_keeps_the_snapshot_a_reset_left_on_disk pins that, and test_a_failed_first_create_leaves_no_snapshot_and_no_temp_file checks that a failed first create leaves result_cache/ as it was. Both pass on the old code too, so they are here rather than in the red commit. The docs are left to the #216 rebase, which describes the write path as built. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
paddymul
force-pushed
the
docs/adr-007-009-implemented
branch
from
September 24, 2026 12:01
ede92d6 to
dba53ea
Compare
paddymul
added a commit
that referenced
this pull request
Sep 24, 2026
ADR-011's own status line no longer says four docs wait on #216. ADR-008's list of open defects drops #197, #198 and #211, which were about the ordered copy ADR-011 replaced. The notes on recalc-mechanism, auto-recalc-on-revise, cache-soundness-audit and datafusion-scan-order-findings say what ADR-011 changed (no source axis, imports trigger auto-recalc, polars parses only a CSV at import, pins name a version). ADR-005's example import call uses the tool's reader_options argument. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
architecture.md is rewritten as the end-to-end overview and map: a glossary of the project's terms, the component map, the full on-disk layout, one section per core concept (identity, worthy and cheap entries, materialization, reads and heals, ordered copies and row order, the digest, staleness, recalc, portability, checkpoint and reset, the project lock, SSE), the request paths, a list of the known defects, and currency notes dated 2026-09-22 that list ADR-010 as rejected. The other docs are corrected against the code on this branch: what the project lock covers, when a failed build deletes a snapshot, how pins are lost, what the SPA listens for, what Buckaroo 0.15.6 ignores or cannot find, the notebook page's session loads, the 31st MCP tool, klass file paths, the pinned_expr_from_alias contract, the staleness scan's live-head rule and its digest-memo rewrite, and the recipe examples, which now pass the build checks. Where the code does not yet do what a doc would promise, the doc says what it does and cites the open issue. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…02 to ADR-006 ADR-007, ADR-008 and ADR-009 are marked "Accepted (2026-09-22). Implemented in #189", keeping their history lines, and each names the open defects from the review of #189 that touch it. The status blocks of the older ADRs say which later decision replaced what: ADR-003 (not adopted; its classifier target and motivating case were overtaken by ADR-008 D4 and ADR-007 D3, its budget half is still open), ADR-004 (digest by ADR-009 D2, the row-index column and every-sort tie-break by ADR-008), ADR-005 (INV-3's key and location by ADR-007 D13, and its deferred drift check now exists), ADR-006 (D2's snapshot path and D10's session eviction). ADR-002 gets a short status note. ADR-010 is unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…hanged Plans and research notes stay point-in-time records. Each of these asserts current behaviour that the read-path fix (#167) or the cache redesign (#189) changed, so each gets a short dated status note saying what no longer holds and where the current behaviour is described. Nothing else in them changes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
ADR-011 held back docs/architecture.md, caching.md, expression-lifecycle.md and system-contract.md until this PR landed, so they would be rewritten once. Now that the PR is rebased onto the merged ADR-011 stack (#217, #218, #219), they describe what exists: a file enters only by catalog_import_source, as a source entry under a source alias; a source entry's hash is an md5 of its bytes and reader options; its snapshot is cache, healed from the clone under data/.cas, and pinned once the clone is gone; recipes name aliases, never files or bare hashes; alias kinds and the rule that an alias's kind matches its entries; one set of bytes is one version under one alias; and staleness has one axis. The ordered copy, the identity modes, manifest.sources, the source-digest memo and the source axis are gone from every doc except where one says what was removed. Known defects #197, #198, #207, #211 and #191, and the two staleness defects with no issue, move to a note that they no longer apply. reactive-recalc.md's walk-through now imports orders and advances it by a re-import. mcp-server.md, installing.md (TALLYMAN_SOURCE_IDENTITY is gone), the README and the code-derived sections of tallyman_explanation.md follow suit. The #193 to #196 passages are unchanged; those fixes are being ported onto this branch separately. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ADR-011's own status line no longer says four docs wait on #216. ADR-008's list of open defects drops #197, #198 and #211, which were about the ordered copy ADR-011 replaced. The notes on recalc-mechanism, auto-recalc-on-revise, cache-soundness-audit and datafusion-scan-order-findings say what ADR-011 changed (no source axis, imports trigger auto-recalc, polars parses only a CSV at import, pins name a version). ADR-005's example import call uses the tool's reader_options argument. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ifest pin #222 and #223 are merged into this branch, so the docs describe the fixed behaviour instead of citing the defects. #193 (#222): a create materializes to a temp name and the build publishes the snapshot after the manifest, so a failed build leaves the file already at the path. A source entry needs no staging. docs/system-contract.md's write-path step 6 and an ADR-007 implementation note say so again, as #213 had. #194 to #196 (#223): the pin is read from the manifest alone (reproducible: false, unfaithful_heal_digest, or a source entry whose clone is gone), so it moves through a reset and outlasts the error banner's dismiss; a retired entry's snapshot is judged by its parked manifest and listed as retired on the Cache page; a reset lets the live entry dir replace a parked one unless it has no manifest; errors.jsonl readers skip a line that is not a JSON object. Sentences that said the error log holds the pin, that nothing rewrites a manifest, and that nothing live reads the bullpen are corrected. The four issues leave architecture.md's Known defects and system-contract.md's Known deviations with a note that they were fixed; ADR-007, ADR-008 and ADR-009's status lines say so too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
paddymul
force-pushed
the
docs/adr-007-009-implemented
branch
from
September 24, 2026 12:16
dba53ea to
357f0a2
Compare
…tory ADR-011's Status is now "Accepted (2026-09-22), implemented." and nothing more. Which PR held which stage, the stacking, the review round and the note about this PR's docs are gone. What it amends is its own bullet, with one line per ADR. The origin of the design and Paddy's two quotes move into Context. The body describes what the system does: the implementation notes lose their stage and PR headings and their order of events, D1 and D3 absorb the review fixes as plain rules, the interim notes that no longer apply are dropped, the Tickets line names the issues whose mechanisms it removed, and Affected code becomes the code that implements it. The other plan headers this PR edited get the same treatment. ADR-007, ADR-008 and ADR-009 say "Accepted (2026-09-22), implemented", name their open defects, and keep what they supersede or amend as bullets, without the proposal's revision history. ADR-005's status says it is implemented and amended by ADR-008 and ADR-011, and ADR-002's what ADR-011 narrowed. The status notes of recalc-mechanism, auto-recalc-on-revise, cache-soundness-audit and datafusion-scan-order-findings state the current behaviour without the sequence of changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sms, header history Checked against the code at 1f8cb02. Contradictions: nothing reads the recipe zip back, so a clone does not recreate entry directories from it; a promoted diff's generated recipe names its two entries by hash and records no parent edge, the one exception to "every edge names an alias"; a source entry's snapshot is written by the import's writer, not materialize, so invariant I2 names both; three kinds of snapshot are pinned, and the pin also depends on whether a source's clone is on disk; import's notebook_changed fires when it mints v1; ADR-007's list of ADR-006 decisions now matches ADR-006's own account; a source entry heals from its clone, not its build; the publish is the last write to the entry's result, not the build's; auto-recalc also follows an import and a re-pointing promoted diff; the compute_cache/ exception applies to xo.deferred_read_parquet only. Leftovers: the README intro no longer says a raw file changing on disk is an update; the self-reference advice pins by version, not hash; ADR-007 and ADR-009 say ADR-011 removed the ordered copies they describe; the status notes of ADR-002, ds-demo-scripts, native-catalog-store and remove-ondemand-result-parquet drop the default and salt modes and the calls that no longer run. Citations and headers: #168's mechanism is gone but the issue is open; #90 is dropped from the contract; PR and commit references come out of the status lines #216 added, and ADR-004's status says Option A is implemented. Tidy: the clone store is named instead of "the arena", "bullpen" is defined at first use in the contract, and two stray tool-call lines are removed from the end of installing.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
plans/open-bugs-2026-09-24.md lists every open issue checked against 1f8cb02, by priority, with the ones that are fixed or obsolete but still open. architecture-new.md's known defects cite an issue for each item. caching.md, expression-lifecycle.md, reactive-recalc.md and system-contract.md now match the code on the re-import of a lost clone, the prompt-log order, the manual recalc path and a source entry's build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Sep 24, 2026
…implemented Brings in #242, #244, #245 and #241. Resolves docs/installing.md: keeps this branch's environment table (with TALLYMAN_COMPANION_URL now read from the data dir's server.lock) and its troubleshooting list, with #241's two bullets in place of the old port-7860 one, and without the stray tags this branch had already removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #189: the base is
feat/adr-007-009-cache-redesign, notmain. Docs only; no code or test changes, and ADR-010's text is untouched.Rebased on 2026-09-24 onto #189's branch after the ADR-011 stack (#217, #218, #219) was merged into it, and extended to cover ADR-011. ADR-011 (a raw input is a source alias whose versions are entries, a file enters only by
catalog_import_source, recipes name aliases and never bare hashes, and staleness has one axis) held backdocs/architecture.md,docs/caching.md,docs/expression-lifecycle.mdanddocs/system-contract.mduntil this PR landed, so they would be rewritten once. They are rewritten now, in 5b6c163, with the rest of the docs; 2650674 updates the plans' status notes. The first three commits are the original ones, rebased; the only conflicts were in the status notes of ADR-002 and ADR-005, which ADR-011 had also edited, and both keep ADR-011's notes with this PR's merged in after them.Rebased again on 2026-09-24 onto 1f8cb02, after #222 (the #193 fix) and #223 (the #194 to #196 fixes) were merged. The rebase had no conflicts. 357f0a2 rewrites every passage about those four issues to describe the fixed behaviour: a create stages its snapshot at a temp name and publishes it after the manifest, so a failed build leaves the file already at the path; the pin is read from the manifest alone (
reproducible: false,unfaithful_heal_digest, or a source entry whose clone is gone), so it moves through a reset and outlasts the error banner's dismiss; a retired entry's snapshot is judged by the manifest parked in the bullpen and listed asretiredon the Cache page; a reset lets the live entry dir replace a parked one unless it has no manifest; anderrors.jsonlreaders skip a line that is not a JSON object. It also corrects the sentences that said the error log holds the pin, that nothing rewrites a manifest, and that nothing live reads the bullpen, and restores thedocs/system-contract.mdwrite-path step and ADR-007 implementation note that #213 had written and the port left out.ADR headers state the design as built (f98bd07). At Paddy's request the plan headers this PR edited carry no merge or rebase history. ADR-011's Status is "Accepted (2026-09-22), implemented."; what it amends is its own bullet; the origin and Paddy's two quotes are in Context; and its body describes what the system does, with implementation notes that carry no PR numbers or order of events. ADR-002, ADR-005, ADR-007, ADR-008 and ADR-009 state their final status with amends, supersedes and amended-by bullets, and the status notes of recalc-mechanism, auto-recalc-on-revise, cache-soundness-audit and datafusion-scan-order-findings state current behaviour only.
Coherence pass (a61943b), checked against the code at 1f8cb02. It corrects claims that contradicted the code: nothing reads the recipe zip back; a promoted diff's recipe names two entries by hash and records no edge; a source entry's snapshot has its own writer, so invariant I2 names two; three kinds of snapshot are pinned, and a pin also depends on whether a source's clone is on disk; ADR-007's account of ADR-006 now matches ADR-006; auto-recalc also follows an import and a re-pointing promoted diff. It also removes leftover mentions of removed mechanisms (hash pins, ordered copies,
saltmode,catalog_load_parquet), fixes the #90 and #168 citations, takes PR and commit references out of the status lines this PR added, and deletes two stray tool-call lines from the end ofdocs/installing.md.docs/architecture-new.md(71f9264, cf446c6) is a new description of the system as built after ADR-011, meant to be read in one sitting. It was written from scratch against the code at 1f8cb02, using the other docs and the ADRs only as sources, anddocs/architecture.mdis left as it was. Its Known defects section adds two defects with no issue, each confirmed with a probe in a scratch home:catalog_import_sourcelets a CSV that fails to parse escape as a plainValueError, with nothing written toerrors.jsonl, and importing a version's bytes again restores a lost clone only when the snapshot is gone too.plans/open-bugs-2026-09-24.md(5ce41b7) lists every open issue checked against 1f8cb02, by priority, including the ones that are fixed or obsolete but still open. importing a parquet file with a fixed_size_binary column fails with a KeyError traceback that names no column #224 to alias, notebook and config writes are read-modify-write with no lock, so two overlapping writers lose one change #240 were filed from this pass, and the known-defects lists inarchitecture-new.mdandarchitecture.mdcite them.feat/adr-007-009-cache-redesignat 63bcdd6, which brings in fix(xorq): executions on the shared backend run one at a time per process (#118) #242 (caching: concurrent .execute() on the shared default backend raises "Already borrowed" — api_data has no execute lock (second cause of #79 two-tab 500) #118), fix(csv): a zone on offset-less CSV text is attached to the wall-clock time (#231) #244 (a tz-aware timestamp in an import schema reads offset-less text as UTC and converts it, contrary to ADR-005 D9(a) #231), fix(cache): a read refuses a directory with no manifest instead of guessing its worthiness from the snapshot (#204) #245 (cache_worthy falls back to "a snapshot exists" when the manifest is missing — a worthy entry that has lost both is served as cheap #204) and fix: one tallyman server per data dir, and a second tallyman on its own data dir reaches its own companion (#183) #241 (two tallyman servers on one project is unsupported and nothing detects it — each holds in-process state the other never sees #183). 9efffe3 describes the fixed behaviour and takes the four out of the defect lists (architecture-new.md,architecture.md,caching.md,system-contract.md, ADR-007's Tickets and D11, andopen-bugs-2026-09-24.md, which moves them to "Closed in this pass"). The docs now describe a process-wide execution lock around every execution on the shared backend, taken after the project lock; onetallyman runper data dir, held through<data dir>/server.lock, whose owner record is the only way a client finds its companion; every read refusing an entry dir with no manifest, with aBuildErrorand a 500 from the entry routes; and a zoned CSV timestamp parsed in its zone. It also dropsTALLYMAN_COMPANION_URLfromdocs/installing.md, since nothing reads it.The docs describe the system as it is on #189's branch, where ADR-007, ADR-008, ADR-009 and ADR-011 are implemented. Where an open issue says the code does not yet do what a doc would promise (#199 to #210 except #204, #185 to #188, #190, and a few older ones such as #157 and #170), the doc describes what the code does and cites the issue. #193 to #196 (#222, #223) and #118, #183, #204 and #231 (#242, #241, #245, #244) are fixed on this branch and are described as fixed.
Terms, as
docs/architecture.mdnow defines them: an entry is one catalog computation, stored under its content hash. A worthy entry is one tallyman materializes into a snapshot, a parquet file of its rows; a cheap entry is row-preserving over one file and keeps no file of its own. An import (catalog_import_source) is the one way a file enters; it makes a source entry, one version of a source alias, whose snapshot holds the file's rows in file order and whose manifest recordsprovenance. The clone is the imported bytes underdata/.cas/. A heal re-creates a missing snapshot and checks it. The bullpen is the directory a reset moves retired files into.What changed
docs/architecture.mddocs/caching.mdretiredandorphanrows, the bullpen's one live reader, source entries (hash, snapshot, heal from the clone, the pin when the clone is gone), the heal table, what the nondeterminism lint flags, the SPA's missingunfaithful_heallistener, and that Buckaroo 0.15.6 ignoresrow_order_column.docs/expression-lifecycle.mddocs/system-contract.mdprovenance,unfaithful_heal_digest), alias kinds, materialization (the staged publish, pins read from the manifest) and the read path are restated for them; a new "import path" section; one staleness axis; and a "Known deviations" section mapping each open issue to the rule it breaks.docs/reactive-recalc.mdordersand advances it by a re-import; one staleness axis replaces the two;pinned_expr_from_aliastakes a version reference only; the recorded graph ismanifest.parentsalone; the scan output (live,orphan_stale), the cone's live-head filter, the SPA'srecalchandling, and imports in the trigger model.docs/mcp-server.mdcatalog_chart_errors(31 tools), the klass file paths,catalog_diff's__row_orderhandling (#200), the checkpoint and notify conditions, #170 and the display-klass reset gap, and ADR-011's data-sourcing rules, auto-recalc on import and the scan that reads no file.docs/installing.mdTALLYMAN_SOURCE_IDENTITYis gone), and the sharing section (tallyman pack, no grids underserve, #209).README.mdcatalog_import_source), routes, SPA pages and SSE listeners, the recommended prompts, the recipe conventions, and the Buckaroo hand-off and serve and pack notes. In the owner's intro, only the two clauses that described raw files read by programs and changes on disk counting as updates are changed (a61943b).tallyman_explanation.mdplans/ADR-007…,plans/ADR-008…,plans/ADR-009…plans/ADR-003…toplans/ADR-006…plans/ADR-011…plans/ADR-002…and ten other plansWhere the docs and the code disagree in a way that looks like a code bug
These are described in the docs as current behaviour, or found while checking them. None has an issue yet. Two from the first version of this list no longer apply: ADR-011 deleted the source-digest memo the scan wiped, and a hash-pinned child can no longer be written.
active_projectfile, not the MCP session's project.tracked_expr_from_aliasandpinned_expr_from_aliascallresolve_project(), while the MCP tool builds into the session's sticky project. After another session switches projects the recipe looks its aliases up in the other project. Related to no way to pin an MCP process to a project: active-project file outranks TALLYMAN_PROJECT and --project #39._raw_parquet_read_check(build.py:305) allowsxo.deferred_read_parquetof any file under the project'scompute_cache/, so a recipe can readcompute_cache/result_cache/<hash>.parquetdirectly: a bare hash in a recipe (ADR-011 D5) with no parent edge recorded and noensure_materializedfirst. Found by reading the code, not reproduced._verify_self_healfalls through to "execution (caching: a recipe with deferred nondeterminism (sample/now/unordered limit) serves different bytes under one content_hash on recompute — hash-invisible, and it breaks eviction's faithful-recompute assumption #83) — a fixed graph that runs differently each execute, or source drift under off": a source entry has no graph to run, and theoffmode is gone. The likely cause for a source entry is a reader change.catalog_listdoes not show an alias's kind, though ADR-011 D1 records the kind "socatalog_listcan separate inputs from computations". The docs do not claim it does.recon_cas_pathhas no callers. ADR-011 D9 describes its error branch, but nothing calls it.entry_added(both promote paths),alias_changed,alias_renamed,display_changed,project_resetandunfaithful_heal. None of them refreshes an open page, so a promoted diff or a CLIreset-toshows up only after some other event.<project_root>/stats,post_processinganddisplay; tallyman sendsartifacts/. Display klasses load; project stats and post-processing functions never do.catalog_chart_errors,catalog_list_display_klassesandPOST /api/chart_erroreach commit an empty revision per call. Display klasses live outside the catalog repo, so their tools' checkpoints record nothing and a reset does not undo them.tallyman pack --exclude-cacheskips paths containing/cache/, which matches nothing in the current layout. Alias, notebook and chart writes take no lock, so an MCP edit and a browser edit of one file at the same moment can lose one.tests/test_promote_diff.py:253still setsTALLYMAN_SOURCE_IDENTITY, which nothing reads.io.py's module docstring says user code references files underdata/by relative name;tracked_expr_from_aliassays to read by hash withpinned_expr_from_alias, andpinned_expr_from_alias's first line says it takes a content hash, which it refuses;tallyman_read_csvand ADR-005 showedcatalog_import_source(path, alias, separator=...), but the tool takesreader_options={...}(ADR-005 is fixed here);ds_modeling_workflowsays its dataset is a parquet underdata/;paths.pyshows~/.tallyman/;preload_plansays it writes nothing, but loading a build can write.xorq_build_expanded/;api_resetsays a timeline scrubber in the SPA calls it, and nothing does.Checked
Every claim in the edited docs was checked against the code on this branch, and against the installed Buckaroo 0.15.6 wheel for claims about Buckaroo; for the ADR-011 pass, against
source_import.py,io.py,materialize.py,staleness.py,source_identity.py,catalog_state.py,aliases.py,build.pyand the MCP tools. Every relative link and#anchorin the edited docs resolves, andgit diff --checkis clean. CI not watched (docs only).🤖 Generated with Claude Code