DC-STORE-12
DC release enforcedThe semantics version may not be left to memory. The declared semantics-bearing surface
(ci/store-semantics-surface.lock) is content-hashed, and any drift fails CI until the author makes ONE
of two EXPLICIT choices: increase STORE_SEMANTICS_VERSION (stores from the previous binary become
invalid), or record semantics_neutral = true with a rationale naming why what the rules PRODUCE is
unchanged. The lock is append-only, versions are non-decreasing, every entry carries a rationale, and a
non-neutral entry must strictly increase the version. The code constant and the last lock entry must
agree.
- Source
docs/clusters/PREPROD-ENTRY-AUTHORITY/SLICE-P6-store-semantics-version-gate.md
- Introduced in
- PREPROD-ENTRY-AUTHORITY-P6
Enforcement trace
Code
Tests 0
no tests named — gap
Cross-references
Evidence notes
A CONTENT trigger was chosen over the intuitive BEHAVIOURAL one after establishing that a golden replay-corpus fingerprint WOULD HAVE MISSED P3 -- the very change this mechanism exists to catch. P3 altered the authoritative epoch rule and did not move the mainnet corpus at all: preview was spared by numeric accident (its fictitious epoch sat BELOW its real one so the comparison never fired) and preprod is not in the corpus. A behavioural trigger measured against a mainnet-shaped corpus is structurally blind to venue-geometry defects, which is the entire P3/P4 family; a content trigger is not. Accepted cost: a comment-only edit inside the declared surface trips the gate, and declaring semantics_neutral takes one line -- the friction is the point. Negative-tested: surface drift without reconciliation, and a lock version diverging from the code constant, were each mutated and caught.