Invariants / DC-STORE-12

DC-STORE-12

DC release enforced

The semantics version may not be left to memory. The declared semantics-bearing surface (ci/store-semantics-surface.lock) is content-hashed, and any drift fails CI until the author makes ONE of two EXPLICIT choices: increase STORE_SEMANTICS_VERSION (stores from the previous binary become invalid), or record semantics_neutral = true with a rationale naming why what the rules PRODUCE is unchanged. The lock is append-only, versions are non-decreasing, every entry carries a rationale, and a non-neutral entry must strictly increase the version. The code constant and the last lock entry must agree.

Source

docs/clusters/PREPROD-ENTRY-AUTHORITY/SLICE-P6-store-semantics-version-gate.md

Introduced in
PREPROD-ENTRY-AUTHORITY-P6

Enforcement trace

Cross-references

Evidence notes

A CONTENT trigger was chosen over the intuitive BEHAVIOURAL one after establishing that a golden replay-corpus fingerprint WOULD HAVE MISSED P3 -- the very change this mechanism exists to catch. P3 altered the authoritative epoch rule and did not move the mainnet corpus at all: preview was spared by numeric accident (its fictitious epoch sat BELOW its real one so the comparison never fired) and preprod is not in the corpus. A behavioural trigger measured against a mainnet-shaped corpus is structurally blind to venue-geometry defects, which is the entire P3/P4 family; a content trigger is not. Accepted cost: a comment-only edit inside the declared surface trips the gate, and declaring semantics_neutral takes one line -- the friction is the point. Negative-tested: surface drift without reconciliation, and a lock version diverging from the code constant, were each mutated and caught.