Files
Aura/docs/design/contracts/c03-single-merge.md
T
claude 8688a60ded docs(ledger): split the design ledger into an INDEX map, per-contract live files, and history sidecars
The single-file ledger had grown to 2968 lines / ~42k tokens, mixing
current design law with accreted history: 59 cycle-stamped realization
blocks, 18 [HISTORY] passages, 22 supersession markers, and the C10 /
C22 / C24 reframe sagas layered several supersessions deep. A
code-grounding audit (31 agents, adversarially verified) confirmed 11
defects stated as current truth: stale crate homes from the C28 #288
roster split (cost nodes, PositionManagement, PositionEvent, Session),
the renamed InputSpec->PortSpec, the pre-#241 project model in C16 and
the open-threads section, a stale HarnessKind retirement deferral in
C24, and three C28-internal inconsistencies.

New shape, per the ailang precedent:

- INDEX.md stays the sole addressable entry point: foundation, external
  components, a C-id-keyed contract map (one line per contract), and
  only the genuinely open architectural threads.
- contracts/cNN-<slug>.md carries each contract's current truth only:
  Guarantee / Forbids / Why with ratified refinements integrated, plus
  a code-anchored Current state. All confirmed defects are fixed here;
  crate anchors were re-verified against the tree.
- contracts/cNN-<slug>.history.md (18 sidecars) and INDEX.history.md
  preserve every superseded block verbatim, stamps and issue refs
  intact, under a frozen-record banner. Nothing was deleted: superseded
  design intent remains an addressable working-tree artifact, off the
  per-cycle audit walk.
- Ledger discipline is now stated in INDEX.md: live files are edited in
  place at cycle close, superseded text moves verbatim to the sidecar,
  and a supersession marker in a live file is itself an audit finding.

Every contract file was verified against its old text by an independent
zero-loss pass (statement-by-statement) plus a code-accuracy spot check;
C-ids and contract titles are unchanged, so existing C-id citations in
code, tests, and issues resolve as before.
2026-07-21 16:40:36 +02:00

37 lines
1.8 KiB
Markdown

# C3 — One merge, at ingestion only
**Guarantee.** Heterogeneous timestamped sources are k-way-merged by timestamp
into one chronological cycle stream at the ingestion boundary; source-native
time units (e.g. data-server's Unix-`time_ms`) are normalized there to the
canonical epoch-ns `timestamp` of C7.
**Forbids.** Any merge / as-of join *inside* the graph.
**Why.** A single ordered timeline is the mechanism that makes heterogeneous-rate
sources (news daily-bias + M5 + ticks) causally combinable without leaking the
future. Keeping the merge at one boundary keeps the graph semantics simple.
## Current state
The k-way merge is `Harness::run`'s per-cycle pick of the live source head with
the smallest `(timestamp, source index)` (`crates/aura-engine/src/harness.rs`).
Each `Source` yields records in ascending timestamp order — the ingestion
precondition the merge relies on — and there is no merge or as-of join anywhere
inside the DAG; the engine only routes in-graph edges.
The ms→epoch-ns normalization is a single seam, `aura_ingest::unix_ms_to_epoch_ns`
(`crates/aura-ingest/src/lib.rs`): the data-source ingestion edge transposes the
data-server's Array-of-Structs `M1Parsed` records into aura's Structure-of-Arrays
base columns (C7) and normalizes their Unix-millisecond time to the canonical
epoch-ns `Timestamp` at this one boundary. Both the eager `load_m1_window`
transpose and the lazy streaming `M1FieldSource` route through that same seam.
## See also
- [C4](c04-cycle-granularity.md) — the merged stream is the data-driven cycle
clock; ties break by source declaration order.
- [C2](c02-causality.md) — one ordered timeline is what makes heterogeneous-rate
sources combinable without look-ahead.
- [C7](c07-scalar-soa.md) — the canonical epoch-ns `Timestamp` and the four SoA
base columns the merge normalizes into.